Back
CVE-2017-6517
CRITICAL
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.
Published: Mar 23, 2017
Modified: Jun 17, 2026
CWE-427
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| microsoft | skype | 7.16.0.102 |
GitHub Security Advisory GHSA-jwp2-53m7-g9fp
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote...
References (14)
- http://packetstormsecurity.com/files/141650/Skype-7.16.0.102-DLL-Hijacking.html Exploit, Third Party Advisory, US Government Resource
- http://seclists.org/fulldisclosure/2017/Mar/44 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96969 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038209
- https://technet.microsoft.com/security/cc308575.aspx Not Applicable
- https://twitter.com/tiger_tigerboy/status/755332687141883904 Press/Media Coverage
- https://twitter.com/vysecurity/status/845013670103003138 Press/Media Coverage
- http://packetstormsecurity.com/files/141650/Skype-7.16.0.102-DLL-Hijacking.html Exploit, Third Party Advisory, US Government Resource
- http://seclists.org/fulldisclosure/2017/Mar/44 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96969 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038209
- https://technet.microsoft.com/security/cc308575.aspx Not Applicable
- https://twitter.com/tiger_tigerboy/status/755332687141883904 Press/Media Coverage
- https://twitter.com/vysecurity/status/845013670103003138 Press/Media Coverage
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
46.34%
Top 1% most likely to be exploited
Threat Score
53.1 / 100
Data Sources
NVD
EPSS
GitHub