Microsoft Won't Patch a Severe Skype Vulnerability Anytime Soon

in internet •  7 years ago 

A serious vulnerability has been discovered in Microsoft-owned most popular free web messaging and voice calling service Skyp,It's not because the flaw is unpatchable, but because fixing the vulnerability requires a significant software rewrite, which indicates that the company will need to issue an all-new version of Skype rather than just a patch.

The exploitation of this preferential search order would allow the attacker to hijack the update process by downloading and placing a malicious version of a DLL file into a temporary folder of a Windows PC and renaming it to match a legitimate DLL that can be modified by an unprivileged user without having any special account privileges.
When Skype's update installer tries to find the relevant DLL file, it will find the malicious DLL first, and thereby will install the malicious code.

When Skype's update installer tries to find the relevant DLL file, it will find the malicious DLL first, and thereby will install the malicious code.

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

Good post

great post.
Upvote and resteem.

thanks for sharing internet security info.
keep it up

helpful information.
go ahead.

Nice and greatfull post...
just awesome

Your post about
""Microsoft Won't Patch a Severe Skype Vulnerability Anytime Soon"" is very good

Nice post

Very good info about microsoft

Very very nice post thanks

it's great news for microsoft users.Thanks zahid.
visit my post.Thanks
@oliviaalexa

You got a 1.36% upvote from @postpromoter courtesy of @zahidsun!

Want to promote your posts too? Check out the Steem Bot Tracker website for more info. If you would like to support the development of @postpromoter and the bot tracker please vote for @yabapmatt for witness!