Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-0622

Опубликовано: 08 янв. 2019
Источник: msrc
EPSS Низкий

Описание

Skype for Android Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests.

An attacker who successfully exploited this vulnerability could bypass Android's lockscreen and access a victim's personal information.

To exploit the vulnerability, an attacker would need have physical access to the phone.

The security update addresses the vulnerability by correcting how Skype for Android handles authentication requests.

FAQ

How do I get the update for Skype for Android?

  1. Tap the Google Play icon on your home screen.
  2. Swipe in from the left edge of the screen.
  3. Tap My apps & games.
  4. Tap the Update box next to the Skype app.

Does the vulnerability exist in Skype for Business or the consumer version of Skype?

This vulnerability only affects the consumer version of Skype.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 62%
0.00429
Низкий

Связанные уязвимости

CVSS3: 4.6
nvd
больше 6 лет назад

An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35.

CVSS3: 4.6
github
больше 3 лет назад

An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35.

CVSS3: 5.3
fstec
больше 6 лет назад

Уязвимость программы мгновенного обмена сообщениями Skype для операционных систем Android, позволяющая нарушителю обойти блокировку экрана и получить доступ к защищаемой информации

EPSS

Процентиль: 62%
0.00429
Низкий