Vulnerabilities > Microsoft > Skype > High

DATE CVE VULNERABILITY TITLE RISK
2018-06-26 CVE-2018-0595 Untrusted Search Path vulnerability in Microsoft Skype
Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
microsoft CWE-426
7.8
2018-06-26 CVE-2018-0594 Untrusted Search Path vulnerability in Microsoft Skype
Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
microsoft CWE-426
7.8
2017-06-26 CVE-2017-9948 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Skype 7.2/7.35/7.36
A stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of remote RDP clipboard content within the message box.
network
low complexity
microsoft CWE-119
8.8
2017-01-23 CVE-2016-5720 Permissions, Privileges, and Access Controls vulnerability in Microsoft Skype
Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) msi.dll, (2) dpapi.dll, or (3) cryptui.dll that is located in the current working directory.
local
low complexity
microsoft CWE-264
7.8