PT-2019-1167 · Microsoft · Skype
Published
2019-01-08
·
Updated
2023-09-03
·
CVE-2019-0622
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Skype versions 8.35
Description
The issue is related to errors in handling specific authentication requests, which can allow an attacker to bypass screen lock and access protected information. This is an elevation of privilege issue that exists when Skype for Android fails to properly handle specific authentication requests.
Recommendations
For Skype version 8.35, consider disabling the authentication request handling functionality until a patch is available. Restrict access to the Skype application on locked devices to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Skype