PT-2019-1167 · Microsoft · Skype

CVE-2019-0622

·

Publicado

2019-01-08

·

Atualizado

2023-09-03

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Skype versions 8.35
Description The issue is related to errors in handling specific authentication requests, which can allow an attacker to bypass screen lock and access protected information. This is an elevation of privilege issue that exists when Skype for Android fails to properly handle specific authentication requests.
Recommendations For Skype version 8.35, consider disabling the authentication request handling functionality until a patch is available. Restrict access to the Skype application on locked devices to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00211
CVE-2019-0622

Produtos afetados

Skype