UPDATED 00:01 EDT / JUNE 28 2017

APPS

Critical flaw in Skype allows hackers to crash systems and execute code

A critical new flaw in Microsoft Corp.’s Skype messaging service could allow hackers to crash systems and execute code in them, according to a report published Tuesday.

Discovered by Vulnerability Lab security researcher Benjamin Kunz Mejri, the flaw, described as a stack buffer overflow vulnerability, affects the official Skype clients in versions v7.2, v7.3.5 & v7.3.6. The flaw itself is considered dangerous because it permits a potential hacker to crash the application remotely with an unexpected exception error and thus permits overwriting of active process registers and the ability to execute malicious code.

According to Mejri, the security vulnerability is located in the “clipboard format” within the Skype software. The vulnerability allows attackers to use a remote computer system with a shared clipboard to provoke a “stack buffer overflow” — a process where data is pumped into a given memory allocation in excess of its capacity.

“The limitation of the transmitted size and count for images via print of the remote session clipboard has no secure limitations or restrictions,” Merji explained. “Attackers are able to crash the software with one request to overwrite the EIP register of the active software process. This allows local or remote attackers to execute own codes on the affected and connected computer systems via the Skype software.”

While that may sound technically complicated, the good news is that Vulnerability Lab notified Microsoft of the bug in May, and the team behind Skype developed a fix. Skype versions 7.37.178 and later now include a patch for the vulnerability.

If you’re currently using Skype on Windows, it’s highly advised that you make sure you’re running the latest version to ensure against an attack.

Image: 140988606@N08/Flickr

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.