Skype 'file://' URI Handler Bypass Remote Code Execution Vulnerability
BID:29553
Info
Skype 'file://' URI Handler Bypass Remote Code Execution Vulnerability
| Bugtraq ID: | 29553 |
| Class: | Design Error |
| CVE: |
CVE-2008-1805 CVE-2008-2545 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | Ismael Briones |
| Vulnerable: |
Skype Technologies Skype 3.6 .244 Skype Technologies Skype 3.6 .216 Skype Technologies Skype 3.8.0.115 Skype Technologies Skype 3.6 Skype Technologies Skype 3.5 |
| Not Vulnerable: |
Skype Technologies Skype 3.8.0.139 |
Discussion
Skype 'file://' URI Handler Bypass Remote Code Execution Vulnerability
Skype is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successfully exploiting this issue may compromise the affected application and possibly the underlying computer.
Versions prior to Skype 3.8.0.139 are vulnerable.
Skype is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successfully exploiting this issue may compromise the affected application and possibly the underlying computer.
Versions prior to Skype 3.8.0.139 are vulnerable.
Exploit / POC
Skype 'file://' URI Handler Bypass Remote Code Execution Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Skype 'file://' URI Handler Bypass Remote Code Execution Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
Skype 'file://' URI Handler Bypass Remote Code Execution Vulnerability
References:
References:
- Skype File URI Security Bypass Code Execution Vulnerability (iDefense Labs)
- Skype Homepage (Skype Technologies)
- Skype Windows Download Page (Skype Technologies)
- Skype File URI Security Bypass Code Execution Vulnerability (iDefense Labs
) - SKYPE-SB/2008-003: Skype File URI Security Bypass Code Execution Vulnerability (Skype Technologies)