Software

OSes

That terrifying 'unfixable' Microsoft Skype security flaw: THE TRUTH

Oh yeah, we patched that in October, Windows giant yawns


Microsoft has poured a bucket of cold water on people freaking out over a supposedly unfixable security flaw in Skype.

The infosec world was atwitter this week over fears and headlines of a nasty bug in Redmond's video chat app that apparently cannot be addressed without a massive code rewrite. That the programming blunder was so major, it cannot be simply patched, and Microsoft will have no option but to reengineer Skype for Windows and issue a new release sometime in the future.

Well, it was fixed in October.

Far be it from us to run to Microsoft's rescue, but the vulnerability is present in Skype for Windows versions 7.40 and lower. In October 2017, Microsoft released version 8 without the flaw, so if you kept up to date, you're fine. If you're running version 7, get version 8.

The security cockup allows malware running on a Windows PC to exploit Skype's update mechanism to gain full control over the computer via DLL hijacking. Exploiting the design oversight will grant malicious software, or anyone logged into the box, full system-level privileges. The update tool uses temporary files stored in the %SYSTEMROOT% directory, and it's possible to drop custom DLLs into that folder and have them injected into an installer process that runs with system-level privileges.

So, yeah, install version 8 if you haven't already. Yes, Microsoft doesn't offer it automatically to all users, and that sucks, but at least now you know what to do.

"There was an issue with an older version of the Skype for Windows desktop installer – version 7.40 and lower. The issue was in the program that installs the Skype software – the issue was not in the Skype software itself," Skype program manager Ellen Kilbourne said in a support forum post on Wednesday.

"Customers who have already installed this version of Skype for Windows desktop are not affected. We have removed this older version of Skype for Windows desktop from our website skype.com."

Roses are red, Windows error screens are blue. It's 2018, and an email can still pwn you

READ MORE

The issue was discovered by German researcher Stefan Kanthak, who said he alerted Redmond in September. Kanthak said he was told in October that patching the bug in the software would require a "large code revision," and disclosed details of the flaw this month to warn everyone of the problem.

That revelation sparked a lot of handwringing and speculation the bug would be a "major" ongoing security issue that would prove highly difficult and expensive for Microsoft to address, leaving punters vulnerable for months to escalation-of-privilege attacks via local users and applications.

Microsoft, however, confirmed this week it addressed the coding cockup back in October, and that the vulnerability can be killed off by simply updating Skype. Those running the latest version have been protected for the past few months. We're also not aware of any malware exploiting this security hole.

This will provide a bit of relief to IT administrators who just two days ago were served a massive Patch Tuesday update that addressed 50 CVE-listed vulnerabilities in Redmond's products, and faced the possibility of having to test and deploy an out-of-band patch for Skype, too. ®

Send us news
38 Comments

Windows 95 setup was three programs in a trench coat, Microsoft vet reveals

MS-DOS, a minimal Windows 3.1, and finally the teal delight of Windows 95 awaited installers

Clues to Windows Intelligence found in Windows 11 builds

Somewhere to find AI settings, or just a button to uninstall the operating system once and for all?

Microsoft finally releases a direct-download Windows 11 on Arm ISO

Good news for supporting Windows on Arm devices and adding new ones

Microsoft goes thin client with $349 Windows 365 Link mini PC

Just as good as Apple at making squat boxes, but this one doesn't do very much

Qualcomm's Windows on Arm push would be great – if only it ran all your software

Until compatibility issues are properly addressed, it'll never stand up to x86

Microsoft slaps Windows 11 update hold on hardware connected to eSCL devices

Scanners, printers, and... fax machines?

Security? We've heard of it: How Microsoft plans to better defend Windows

Did we say CrowdStrike? We meant, er, The July Incident...

Microsoft reboots Windows Recall, but users wish they could forget

AI snapshot tool stumbles back into the spotlight with more issues

Arm lays down the law with a blueprint to challenge x86's PC dominance

Now it's up to OEMs and devs to decide whether they want in

Microsoft preps big guns to shift Copilot software and PCs

IT admins be warned: 13,000 tech suppliers coming for your employer's checkbook

Windows 11 continues to creep up behind Windows 10

Dark alley and a brick in a sock required to accelerate market share growth?

Microsoft hits back at claims it slurps your Word, Excel files to train AI models

Confusion over Connected Experiences settings in 365 apps spark concerns