A significant security vulnerability has been identified in Skype, the widely used web messaging and voice calling service owned by Microsoft. This flaw may enable malicious actors to execute code remotely, potentially compromising systems running outdated versions of the application.

Skype has become integral for online communication, offering voice, video, and instant messaging services across the globe. Microsoft acquired the platform in 2011 for $8.5 billion, recognizing its substantial user base. The newly discovered flaw, referred to as a stack buffer overflow vulnerability, was uncovered by German security researcher Benjamin Kunz-Mejri during a team conference call.

The vulnerability is cataloged under the identifier CVE-2017-9948 and poses a significant security risk, scoring 7.2 on the Common Vulnerability Scoring System (CVSS). It impacts versions 7.2, 7.35, and 7.36 of Skype on platforms such as Windows XP, Windows 7, and Windows 8. According to a public disclosure issued by Mejri’s firm, Vulnerability Lab, the flaw allows exploitation through both remote session and local interaction.

The potential for attack is alarming, as the vulnerability does not necessitate any user intervention. A threat actor can leverage a low-privilege Skype account to crash the application through an unexpected exception error. This allows an attacker the ability to overwrite active process registers, effectively seizing control of a target system running the vulnerable version.

The underlying issue relates to how Skype utilizes the ‘MSFTEDIT.DLL’ file, particularly when processing local system copy requests. Attackers could exploit this flaw by crafting a malicious image file, copying it to a clipboard, and then pasting it into the Skype conversation window. Once the image resides on the clipboard of both the local and remote systems, the application would experience a stack buffer overflow, leading to errors and crashes that could facilitate further exploitation.

Vulnerability Lab has indicated that the limitations for the size and number of transmitted images during remote session clipboard operations lack adequate security measures. As noted, “Attackers can crash the software with one request to overwrite the EIP register of the active software process.” This kind of attack may fall under the MITRE ATT&CK tactics of initial access and exploitation of vulnerabilities.

In response to these discoveries, Vulnerability Lab submitted a report to Microsoft on May 16, prompting the tech giant to release a patch on June 8, 2017, as a part of Skype version 7.37.178. For users of Skype, it is imperative to ensure that the current version of the application is installed to mitigate the risk of potential cyber-attacks.

As cybersecurity remains a critical concern for businesses, staying informed of vulnerabilities like this one contributes to better defensive measures against emerging threats. Engaging with comprehensive security practices and timely software updates are essential for maintaining system integrity in the face of evolving cyber risks.

If you found this article informative, follow us on Google News, Twitter, and LinkedIn for more exclusive content.