Lucene search

K
zdiDiscovered by: Hector Peralta (@hperalta89) and Nicolรกs ArmuaZDI-24-293
HistoryMar 13, 2024 - 12:00 a.m.

Microsoft Skype Protection Mechanism Failure Remote Code Execution Vulnerability

2024-03-1300:00:00
Discovered by: Hector Peralta (@hperalta89) and Nicolรกs Armua
www.zerodayinitiative.com
17
microsoft
skype
remote code execution
vulnerability
today tab
context isolation

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

54.9%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Skype. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the implementation of the Today tab. The issue results from the lack of context isolation. An attacker can leverage this vulnerability to execute code in the context of the current process.

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

54.9%