← Back

CVE-2017-6517

nvd nist
Published: Mar 23, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.

Affected (1)

Products: Microsoft: Skype
1 product
Skype
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.16.0.102

References (14)

Source: cve@mitre.org
ExploitThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Not Applicable
Source: cve@mitre.org
Press/Media Coverage
Source: cve@mitre.org
Press/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media Coverage

Timeline

No history available yet.