Vulnerability Description
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Skype | 7.16.0.102 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/141650/Skype-7.16.0.102-DLL-Hijacking.htmlExploitThird Party AdvisoryUS Government Resource
- http://seclists.org/fulldisclosure/2017/Mar/44Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/96969Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038209
- https://technet.microsoft.com/security/cc308575.aspxNot Applicable
- https://twitter.com/tiger_tigerboy/status/755332687141883904Press/Media Coverage
- https://twitter.com/vysecurity/status/845013670103003138Press/Media Coverage
- http://packetstormsecurity.com/files/141650/Skype-7.16.0.102-DLL-Hijacking.htmlExploitThird Party AdvisoryUS Government Resource
- http://seclists.org/fulldisclosure/2017/Mar/44Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/96969Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038209
- https://technet.microsoft.com/security/cc308575.aspxNot Applicable
- https://twitter.com/tiger_tigerboy/status/755332687141883904Press/Media Coverage
- https://twitter.com/vysecurity/status/845013670103003138Press/Media Coverage
FAQ
What is CVE-2017-6517?
CVE-2017-6517 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll...
How severe is CVE-2017-6517?
CVE-2017-6517 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-6517?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Skype.