Skype Web Content Zone Remote Code Execution Vulnerability

BID:27338

Info

Skype Web Content Zone Remote Code Execution Vulnerability

Bugtraq ID: 27338
Class: Design Error
CVE: CVE-2007-5989
CVE-2008-0582
CVE-2008-0583
Remote: Yes
Local: No
Published: Jan 17 2008 12:00AM
Updated: Feb 13 2008 10:16PM
Credit: Aviv are credited with the discovery of this issue. Miroslav Luinskij is credited with the discovery of how to leverage the issue via DailyMotion.
Vulnerable: Skype Technologies Skype 3.6 .244
Skype Technologies Skype 3.6 .216
Skype Technologies Skype 3.6
Skype Technologies Skype 3.5
Not Vulnerable:

Discussion

Skype Web Content Zone Remote Code Execution Vulnerability

Skype is prone to a vulnerability that allows arbitrary code to run. The issue occurs because the application uses Windows 'Web content Zones' in an insecure manner.

Attackers can leverage the issue by enticing an unsuspecting user to use a Skype dialog on a malicious web object. Successful exploits will allow arbitrary code to run in the context of the user running the application.

Skype 3.5 and 3.6 series are vulnerable.

Exploit / POC

Skype Web Content Zone Remote Code Execution Vulnerability

The following video demonstrates an example exploit. The DailyMotion website service allows users to upload videos for public viewing. Due to an input-validation issue affecting the website, attackers can inject arbitrary code in the 'Title' field when uploading videos. When a Skype user accesses DailyMotion via Skype's 'Add video to chat' page and the malicious title is displayed, the attacker's code executes.

http://www.youtube.com/watch?v=FcuQrLZ4AU0

Metacafe videos are also reported to be an attack vector for this issue. Proof-of-concept code is reported to exist, but not publicly available.

Solution / Fix

Skype Web Content Zone Remote Code Execution Vulnerability

Solution:
The vendor released a temporary fix to address this issue. The fix disables the ability to add videos from DailyMotion. The vendor states that an official fix is forthcoming. Please see the references for more information.

UPDATE (January 22, 2008): The vendor has disabled the use of video in Skype until an update is available.

UPDATE (February 6, 2008): Skype has fixed these vulnerabilities in the latest version. Please see the referenced advisories for information about obtaining fixes.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report