A new vulnerability has been discovered in Microsoft, this time in the desktop version of the Skype application on Windows.
Security researcher Benjamin Kunz Mejri explains that the bug, which was documented as CVE-2017-9948, is found in Skype versions 7.2, 7.35, and 7.36.

The downside? The vulnerability does not require user interaction, and an attacker could crash the application or even execute malicious code on a system running the vulnerable version of the application.
The source of the problem is a security flaw in the MSFTEDIT.DLL library, which can be exploited by an attacker by copying a malicious image file to the clipboard and pasting it into a chat window in the application. Once the photo is saved on both the remote and local systems, Skype suffers a stack buffer overflow, leaving the door open for more exploits.
A successful attack is not limited to manual exploitation since hackers can locally prepare a system's memory and clipboard to exploit the remotely connected system via Skype.
The buffer overflow vulnerability does not require user interaction, just a simple Skype account. Successful infection leads to registry overwrites.
Luckily, Microsoft has already fixed the bug for version 7.37.178 and recommends that users install it as soon as possible to avoid the risk of infection. The patch was released on June 8.
At this point, there are no reports of successful attacks due to this bug, but it is essential that Skype users update their software as soon as possible.
