CVE-2018-0595: High severity skype vulnerability
Published Jun 26, 2018
·Updated
Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
2 affected components
Microsoft Skype
Microsoft Windows
Event History
Jun 26, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0595?
CVE-2018-0595 is an untrusted search path vulnerability in the installer of Skype for Windows.
2
How does CVE-2018-0595 work?
This vulnerability allows an attacker to gain privileges by placing a Trojan horse DLL in an unspecified directory.
3
Which software is affected by CVE-2018-0595?
Skype for Windows is affected by CVE-2018-0595.
4
What is the severity of CVE-2018-0595?
CVE-2018-0595 has a severity rating of 7.8 (high).
5
How can I fix CVE-2018-0595?
To fix CVE-2018-0595, it is recommended to update Skype for Windows to the latest version.