MS15-116 and MS15-123: Description of the security update for Skype for Business 2016: November 10, 2015

Applies to: Skype for Business 2016


This security update resolves vulnerabilities in Skype for Business 2016. These vulnerabilities could allow remote code execution if a user opens a specially crafted document or goes to an untrusted webpage that contains embedded OpenType fonts. Or, these vulnerabilities could allow information disclosure if an attacker invites a user to an instant message session and then sends that user a message that contains specially crafted JavaScript content.

To learn more about the vulnerabilities, see Microsoft Security Bulletin MS15-116 and Microsoft Security Bulletin MS15-123.

Note After you apply this security update, you may see a popup window that states that a website wants to open web content in protected mode in Internet Explorer. See Updates to change the way that Internet Explorer interacts with features in Microsoft Office applications for more information.

How to get and install the update

Method 1: Microsoft Update

This update is available through Microsoft Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Get security updates automatically.

Method 2: Microsoft Download Center

You can get the stand-alone update package through the Microsoft Download Center. To install the update, follow the installation instructions on the download page. 

Update deployment information

For deployment information about this update, see Microsoft Knowledge Base article 3104540 and 3105872.


There are no prerequisites to install this security update.

Update replacement information

This update replaces previously released update 2910994.