First published: Thu Aug 26 2010(Updated: )
Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32.dll that is located in the same folder as a .skype file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Skype | =3.1.0.134-beta | |
Microsoft Skype | =2.5.0.154 | |
Microsoft Skype | =3.8.0.154 | |
Microsoft Skype | =0.98.0.6-beta | |
Microsoft Skype | =0.97.0.3-beta | |
Microsoft Skype | =4.2.0.166 | |
Microsoft Skype | =3.2.0.145 | |
Microsoft Skype | =3.2.0.158 | |
Microsoft Skype | =1.2.0.41 | |
Microsoft Skype | =4.2.0.158 | |
Microsoft Skype | =1.3.0.57 | |
Microsoft Skype | =3.8.0.96-beta | |
Microsoft Skype | =3.1.0.144 | |
Microsoft Skype | =1.0.0.94 | |
Microsoft Skype | =4.0.0.226 | |
Microsoft Skype | =0.93.0.18-beta | |
Microsoft Skype | =0.94.0.28-beta | |
Microsoft Skype | =4.0.0.227 | |
Microsoft Skype | =0.95.0.11-beta | |
Microsoft Skype | =0.92.0.4-beta | |
Microsoft Skype | =1.0.0.9 | |
Microsoft Skype | =1.0.0.97 | |
Microsoft Skype | =3.2.0.82-beta | |
Microsoft Skype | =3.6.0.127-beta | |
Microsoft Skype | =1.0.0.18 | |
Microsoft Skype | =2.0.0.105 | |
Microsoft Skype | =3.0.0.154-beta | |
Microsoft Skype | =1.0.0.29 | |
Microsoft Skype | =1.4.0.84 | |
Microsoft Skype | =0.98.0.68-beta | |
Microsoft Skype | =2.0.0.81 | |
Microsoft Skype | =2.0.0.103 | |
Microsoft Skype | =2.0.0.90 | |
Microsoft Skype | =1.0.0.106 | |
Microsoft Skype | =2.5.0.130 | |
Microsoft Skype | =3.1.0.152 | |
Microsoft Skype | =3.0.0.106-beta | |
Microsoft Skype | =0.90.0.5-beta | |
Microsoft Skype | =3.5.0.158-beta | |
Microsoft Skype | =4.0.0.166-beta_2 | |
Microsoft Skype | =1.4.0.71 | |
Microsoft Skype | =3.1.0.112-beta | |
Microsoft Skype | =1.3.0.54 | |
Microsoft Skype | =4.0.0.215 | |
Microsoft Skype | =3.6.0.248 | |
Microsoft Skype | =3.5.0.214 | |
Microsoft Skype | =3.2.0.53-beta | |
Microsoft Skype | =0.91.0.2-beta | |
Microsoft Skype | =3.2.0.115-beta | |
Microsoft Skype | =0.96.0.1-beta | |
Microsoft Skype | =1.3.0.48 | |
Microsoft Skype | =3.2.0.148 | |
Microsoft Skype | =2.0.0.107 | |
Microsoft Skype | =1.4.0.78 | |
Microsoft Skype | =1.3.0.66 | |
Microsoft Skype | =1.0.0.10 | |
Microsoft Skype | =3.8.0.115 | |
Microsoft Skype | =3.0.0.205 | |
Microsoft Skype | =4.0.0.150-beta | |
Microsoft Skype | =1.3.0.51 | |
Microsoft Skype | =4.0.0.181-beta_3 | |
Microsoft Skype | =1.1.0.79 | |
Microsoft Skype | =4.0-beta_3 | |
Microsoft Skype | =3.0.0.214 | |
Microsoft Skype | =4.2.0.163 | |
Microsoft Skype | =0.97.0.6-beta | |
Microsoft Skype | =2.6.0.105-beta | |
Microsoft Skype | =4.0.0.168-beta_2 | |
Microsoft Skype | =2.6.0.103-beta | |
Microsoft Skype | =2.5.0.113 | |
Microsoft Skype | =0.93.1.1-beta | |
Microsoft Skype | =1.3.0.55 | |
Microsoft Skype | =2.6.0.67-beta | |
Microsoft Skype | =3.5.0.239 | |
Microsoft Skype | =2.5.0.137 | |
Microsoft Skype | =3.0.0.198 | |
Microsoft Skype | =2.6.0.97-beta | |
Microsoft Skype | =2.6.0.81-beta | |
Microsoft Skype | =3.0.0.190 | |
Microsoft Skype | =2.5.0.82 | |
Microsoft Skype | =1.3.0.60 | |
Microsoft Skype | =3.2.0.175 | |
Microsoft Skype | =2.5.0.122 | |
Microsoft Skype | =3.5.0.107-beta | |
Microsoft Skype | =4.2.0.155 | |
Microsoft Skype | =3.0.0.216 | |
Microsoft Skype | =4.0.0.161-beta | |
Microsoft Skype | =3.6.0.244 | |
Microsoft Skype | =4.0.0.176-beta_3 | |
Microsoft Skype | =1.2.0.48 | |
Microsoft Skype | =3.2.0.63-beta | |
Microsoft Skype | =0.97.0.40-beta | |
Microsoft Skype | =4.1.0.136 | |
Microsoft Skype | =2.0.0.97 | |
Microsoft Skype | =3.2.0.163 | |
Microsoft Skype | =4.2.0.152 | |
Microsoft Skype | =3.8.0.144 | |
Microsoft Skype | =0.96.0.3-beta | |
Microsoft Skype | =0.97.0.1-beta | |
Microsoft Skype | =3.1.0.150 | |
Microsoft Skype | =4.1.0.130-beta | |
Microsoft Skype | =0.94.0.19-beta | |
Microsoft Skype | =3.1.0.147 | |
Microsoft Skype | =0.98.0.28-beta | |
Microsoft Skype | =3.0.0.218 | |
Microsoft Skype | <=4.2.0.169 | |
Microsoft Skype | =4.0.0.224 | |
Microsoft Skype | =3.5.0.234 | |
Microsoft Skype | =2.5.0.151 | |
Microsoft Skype | =1.3.0.45 | |
Microsoft Skype | =2.5.0.126 | |
Microsoft Skype | =4.1.0.130 | |
Microsoft Skype | =3.5.0.229 | |
Microsoft Skype | =3.8.0.188 | |
Microsoft Skype | =4.1.0.141 | |
Microsoft Skype | =4.0.0.206 | |
Microsoft Skype | =2.6.0.74-beta | |
Microsoft Skype | =4.1.0.179 | |
Microsoft Skype | =3.8.0.180 | |
Microsoft Skype | =2.0.0.73 | |
Microsoft Skype | =3.0.0.137-beta | |
Microsoft Skype | =4.0.0.145-beta | |
Microsoft Skype | =0.98.0.04-beta | |
Microsoft Skype | =3.2.0.152 | |
Microsoft Skype | =4.0.0.155-beta_1 | |
Microsoft Skype | =0.95.0.36-beta | |
Microsoft Skype | =0.98.0.42-beta | |
Microsoft Skype | =3.0.0.123-beta | |
Microsoft Skype | =2.5.0.72 | |
Microsoft Skype | =3.6.0.216 | |
Microsoft Skype | =2.0.0.69 | |
Microsoft Skype | =3.8.0.139 | |
Microsoft Skype | =3.5.0.178 | |
Microsoft Skype | =3.0.0.217 | |
Microsoft Skype | =3.6.0.159-beta | |
Microsoft Skype | =2.5.0.141 | |
Microsoft Skype | =0.90.0.10-beta | |
Microsoft Skype | =0.95.0.25-beta | |
Microsoft Skype | =1.1.0.73 | |
Microsoft Skype | =1.0.0.100 | |
Microsoft Skype | =2.0.0.79 | |
Microsoft Skype | =2.5.0.91 | |
Microsoft Skype | =3.5.0.202 | |
Microsoft Skype | =4.0.0.169-beta_2 | |
Microsoft Skype | =0.95.0.40-beta | |
Microsoft Skype | =4.0.0.216 | |
Microsoft Skype | =4.2.0.141-beta | |
Microsoft Skype | =4.1.0.166 | |
Microsoft Skype | =1.2.0.37 | |
Microsoft Skype | =1.1.0.6 | |
Microsoft Skype | =3.0.0.209 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3136 has a moderate severity rating, allowing local and possibly remote attackers to execute arbitrary code through DLL hijacking.
To fix CVE-2010-3136, users should update to a version of Skype that is later than 4.2.0.169.
The potential impacts of CVE-2010-3136 include unauthorized code execution and potential control over the affected system.
CVE-2010-3136 affects Skype versions up to and including 4.2.0.169.
Primarily, local users or adversaries with local access to the system are affected by CVE-2010-3136.