First published: Mon Jan 23 2017(Updated: )
Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) msi.dll, (2) dpapi.dll, or (3) cryptui.dll that is located in the current working directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Skype |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5720 is classified as a high-severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2016-5720, ensure that you are using the latest version of Microsoft Skype and avoid placing untrusted DLL files in the current working directory.
Local users of Microsoft Skype are affected by CVE-2016-5720 due to the possibility of executing untrusted search paths.
CVE-2016-5720 can facilitate DLL hijacking attacks, allowing malicious users to execute arbitrary code.
You can identify if you are vulnerable to CVE-2016-5720 by checking if your version of Microsoft Skype is outdated and assessing your working directory for untrusted DLL files.