CVE-2017-9948: Buffer Overflow
Published Jun 26, 2017
·Updated
A stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of remote RDP clipboard content within the message box.
Affected Software
3 affected components
Microsoft Skype=7.2
Microsoft Skype=7.35
Microsoft Skype=7.36
Event History
Jun 26, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9948?
CVE-2017-9948 has been rated as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2017-9948?
To resolve CVE-2017-9948, users should update Microsoft Skype to version 7.37 or later.
3
What software versions are affected by CVE-2017-9948?
CVE-2017-9948 affects Microsoft Skype versions 7.2, 7.35, and 7.36 prior to 7.37.
4
What type of vulnerability is CVE-2017-9948?
CVE-2017-9948 is classified as a stack buffer overflow vulnerability.
5
Can CVE-2017-9948 be exploited remotely?
Yes, CVE-2017-9948 can be exploited remotely through the mishandling of RDP clipboard content.