SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-6517

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.

CRITICAL 9.8EPSS 46.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 46.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
46.34% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-427
Affected
microsoft/skype
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.