A stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of remote RDP clipboard content within the message box.
References
Link | Resource |
---|---|
https://www.vulnerability-lab.com/get_content.php?id=2084 | Mailing List Third Party Advisory |
https://www.vulnerability-lab.com/get_content.php?id=2071 | Mailing List Third Party Advisory |
https://www.vulnerability-db.com/?q=articles/2017/05/28/stack-buffer-overflow-zero-day-vulnerability-uncovered-microsoft-skype-v72-v735 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/99281 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-06-26 07:29
Updated : 2017-07-05 10:01
NVD link : CVE-2017-9948
Mitre link : CVE-2017-9948
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
microsoft
- skype