CVE-2017-6517

9.8 CRITICAL
Published: March 23, 2017 Modified: May 13, 2026
View on NVD

Description

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://packetstormsecurity.com/files/141650/Skype-7.16.0.102-DLL-Hijacking.html
Source: cve@mitre.org
Exploit Third Party Advisory US Government Resource
http://seclists.org/fulldisclosure/2017/Mar/44
Source: cve@mitre.org
Mailing List Third Party Advisory
http://www.securityfocus.com/bid/96969
Source: cve@mitre.org
Third Party Advisory VDB Entry
https://technet.microsoft.com/security/cc308575.aspx
Source: cve@mitre.org
Not Applicable
https://twitter.com/tiger_tigerboy/status/755332687141883904
Source: cve@mitre.org
Press/Media Coverage
https://twitter.com/vysecurity/status/845013670103003138
Source: cve@mitre.org
Press/Media Coverage
http://packetstormsecurity.com/files/141650/Skype-7.16.0.102-DLL-Hijacking.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Third Party Advisory US Government Resource
http://seclists.org/fulldisclosure/2017/Mar/44
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory
http://www.securityfocus.com/bid/96969
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1038209
Source: af854a3a-2127-422b-91ae-364da2661108
https://technet.microsoft.com/security/cc308575.aspx
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
https://twitter.com/tiger_tigerboy/status/755332687141883904
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media Coverage
https://twitter.com/vysecurity/status/845013670103003138
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media Coverage

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
9.8 / 10.0
EPSS (Exploit Probability)
46.3%
99th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

microsoft