PT-2017-1606 · Microsoft · Skype+1
Sachin Wagh
+1
·
Published
2017-03-23
·
Updated
2019-10-03
·
CVE-2017-6517
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Skype version 7.16.0.102
Description
The issue exists due to the way .dll files are loaded by Skype, allowing an unauthenticated, remote attacker to execute arbitrary code on the targeted system. The specific flaw is within the handling of DLL loading by the Skype.exe process, particularly with the api-ms-win-core-winrt-string-l1-1-0.dll. An attacker can exploit this by loading a specially crafted .dll file, potentially executing arbitrary code without the user's knowledge.
Recommendations
For Microsoft Skype version 7.16.0.102, consider restricting the loading of external libraries to prevent exploitation until a patch is available. As a temporary workaround, avoid using the Skype.exe process to load .dll files from untrusted sources, especially the api-ms-win-core-winrt-string-l1-1-0.dll, to minimize the risk of arbitrary code execution.
Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Skype
Api-Ms-Win-Core-Winrt-String-L1-1-0.Dll