PT-2005-4078 · Microsoft · Skype For Windows+1

Mark Rowe

·

Published

2005-10-27

·

Updated

2017-07-11

·

CVE-2005-3265

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Skype for Windows versions 1.1.x.0 through 1.4.x.83
Description The issue allows remote attackers to execute arbitrary code via (1) "callto://" and (2) "skype://" links, or (3) a non-standard VCARD, possibly due to an underlying error in the SysUtils.WideFmtStr Delphi routine.
Recommendations For Skype for Windows versions 1.1.x.0 through 1.4.x.83, consider disabling the handling of "callto://" and "skype://" links, as well as non-standard VCARDs, until a patch is available. Restrict access to the SysUtils.WideFmtStr Delphi routine to minimize the risk of exploitation.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-3265

Affected Products

Skype
Skype For Windows