Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6517

Опубликовано: 23 мар. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Средний

Описание

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:microsoft:skype:7.16.0.102:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.1974
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.

fstec
почти 9 лет назад

Уязвимость программы мгновенного обмена сообщениями Skype, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 95%
0.1974
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-427