CVE-2017-6517
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 46.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 46.34% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- microsoft/skype
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/141650/Skype-7.16.0.102-DLL-Hijacking.htmlExploit, Third Party Advisory, US Government Resource
- http://seclists.org/fulldisclosure/2017/Mar/44Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96969Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038209
- https://technet.microsoft.com/security/cc308575.aspxNot Applicable
- https://twitter.com/tiger_tigerboy/status/755332687141883904Press/Media Coverage
- https://twitter.com/vysecurity/status/845013670103003138Press/Media Coverage
- http://packetstormsecurity.com/files/141650/Skype-7.16.0.102-DLL-Hijacking.htmlExploit, Third Party Advisory, US Government Resource
- http://seclists.org/fulldisclosure/2017/Mar/44Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96969Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038209
- https://technet.microsoft.com/security/cc308575.aspxNot Applicable
- https://twitter.com/tiger_tigerboy/status/755332687141883904Press/Media Coverage
- https://twitter.com/vysecurity/status/845013670103003138Press/Media Coverage
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.