CVE-2016-5720
HIGHMicrosoft Skype - Untrusted Search Path Vulnerability via DLL Hijacking
Title source: llmDescription
Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) msi.dll, (2) dpapi.dll, or (3) cryptui.dll that is located in the current working directory.
References (2)
Core 2
Core References
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Sep/65
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/95859
Scores
CVSS v3
7.8
EPSS
0.0187
EPSS Percentile
77.3%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (1)
microsoft/skype
Published
Jan 23, 2017
Tracked Since
Feb 18, 2026