Vulnerability Description
Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Client's microphone and camera access.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Skype | <= 8.59.0.77 |
References
- https://www.hdwsec.fr/blog/20200608-skype/ExploitThird Party Advisory
- https://www.hdwsec.fr/blog/20200608-skype/ExploitThird Party Advisory
FAQ
What is CVE-2020-24003?
CVE-2020-24003 is a vulnerability with a CVSS score of 3.3 (LOW). Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access b...
How severe is CVE-2020-24003?
CVE-2020-24003 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24003?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Skype.