{"id":4468,"date":"2018-02-14T20:49:24","date_gmt":"2018-02-14T15:19:24","guid":{"rendered":"https:\/\/qadit.com\/blog\/?p=4468"},"modified":"2018-02-14T20:49:24","modified_gmt":"2018-02-14T15:19:24","slug":"microsoft-wont-patch-a-severe-skype-vulnerability-anytime-soon","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/microsoft-wont-patch-a-severe-skype-vulnerability-anytime-soon\/","title":{"rendered":"Microsoft Won&#8217;t Patch a Severe Skype Vulnerability Anytime Soon"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/1.bp.blogspot.com\/-lK_gxcxu7xQ\/WoQEHgw1sjI\/AAAAAAAAvyI\/Gw-cBPy8z98ShJFmuz9aewOwYG7zxuanQCLcBGAs\/s1600-e20\/skype-hacking.png\" title=\"Microsoft Won't Patch a Severe Skype Vulnerability Anytime Soon\"><\/p>\n<div>\n<div dir=\"ltr\">\n<p>\nA serious vulnerability has been discovered in Microsoft-owned most popular free web messaging and voice calling service Skype that could potentially allow attackers to gain full control of the host machine by granting system-level privileges to a local, unprivileged user.\n<\/p>\n<p>\nThe worst part is that this vulnerability will not be patched by Microsoft anytime soon.\n<\/p>\n<p>\nIt&#8217;s not because the flaw is unpatchable, but because fixing the vulnerability requires a significant software rewrite, which indicates that the company will need to issue an all-new version of Skype rather than just a patch.\n<\/p>\n<p>\nThe vulnerability has been <\/p>\n<p><a href=\"https:\/\/capec.mitre.org\/data\/definitions\/471.html\" rel=\"nofollow\" target=\"_blank\">discovered<\/a><\/p>\n<p> and reported to Microsoft by security researcher Stefan Kanthak and resides in Skype&#8217;s update installer, which is susceptible to Dynamic Link Libraries (DLL) hijacking.\n<\/p>\n<p>\nAccording to the researcher, a potential attacker could exploit the &#8220;functionality of the Windows DLL loader where the process loading the DLL searches for the DLL to be loaded first in the same directory in which the process binary resides and then in other directories.&#8221;\n<\/p>\n<p>\nThe exploitation of this preferential search order would allow the attacker to hijack the update process by downloading and placing a malicious version of a DLL file into a temporary folder of a Windows PC and renaming it to match a legitimate DLL that can be modified by an unprivileged user without having any special account privileges.\n<\/p>\n<p>\nWhen Skype&#8217;s update installer tries to find the relevant DLL file, it will find the malicious DLL first, and thereby will install the malicious code.\n<\/p>\n<p>\nAlthough Kanthak demonstrated the attack using the Windows version of Skype, he believes the same DLL hijacking method could also work against other operating systems, including Skype versions for macOS and Linux.\n<\/p>\n<p>\nKanthak informed Microsoft of the Skype vulnerability back in September, but the company told him that the patch would require the Skype update installer go through &#8220;a large code revision,&#8221; Kanthak <\/p>\n<p><a href=\"http:\/\/www.zdnet.com\/article\/skype-cannot-fix-security-bug-without-a-massive-code-rewrite\/\" rel=\"nofollow\" target=\"_blank\">told<\/a><\/p>\n<p> ZDNet.\n<\/p>\n<p>\nSo rather than releasing a security update, Microsoft decided to build an altogether new version of the Skype client that would address the vulnerability.\n<\/p>\n<p>\nIt should be noted that this vulnerability only affects the Skype for the desktop app, which uses its update installer which is vulnerable to the DLL hijacking technique. The Universal Windows Platform (UWP) app version available from the Microsoft Store for Windows 10 PCs is not affected.\n<\/p>\n<blockquote class=\"tr_bq\"><p>\nThe vulnerability has been rated as &#8220;medium&#8221; in severity, but Kanthak said, &#8220;the attack could be easily weaponized.&#8221; He gave two examples, which have not been released yet.<\/p><\/blockquote>\n<p>\nUntil the company issues an all-new version of Skype client, users are advised to exercise caution and avoid clicking on attachments provided in an email. Also, make sure you run appropriate and updated anti-virus software that offers some defence against such attacks.\n<\/p>\n<p>\nThis is not the first time Skype has been dealing with a severe security flaw. In June 2017, a <\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2017\/06\/skype-crash-bug.html\" target=\"_blank\">critical flaw in Skype<\/a><\/p>\n<p> was revealed before Microsoft released a fix for the issue that allowed hackers to crash systems and execute malicious code in them.\n<\/p>\n<p>\nLast month, among several messaging applications, Skype was also dealing with a critical remote code execution <\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2018\/01\/electron-js-hacking.html\" target=\"_blank\">vulnerability in Electron<\/a><\/p>\n<p>\u2014a popular web application framework widely-used in desktop applications.<\/p>\n<\/div>\n<\/div>\n<p><b>Read the Full Article here: <a href=\"https:\/\/thehackernews.com\/\">&gt;The Hacker News [ THN ]<\/a><\/b><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A serious vulnerability has been discovered in Microsoft-owned most popular free web messaging and voice calling service Skype that could potentially allow attackers to gain full control of the host machine by granting system-level privileges to a local, unprivileged user. The worst part is that this vulnerability will not be patched by Microsoft anytime soon. &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/microsoft-wont-patch-a-severe-skype-vulnerability-anytime-soon\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Microsoft Won&#8217;t Patch a Severe Skype Vulnerability Anytime Soon&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[12],"tags":[293],"class_list":["post-4468","post","type-post","status-publish","format-standard","hentry","category-itsec","tag-wonder-information"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-1a4","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4468","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=4468"}],"version-history":[{"count":1,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4468\/revisions"}],"predecessor-version":[{"id":4469,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4468\/revisions\/4469"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=4468"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=4468"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=4468"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}