A major bug is forcing Microsoft to rebuild Skype for Windows

Skype has fallen foul of a security flaw that can allow attackers to gain system-level privileges to vulnerable computers, Microsoft has confirmed. However, the company won't immediately fix the issue because doing so would require a complete code overhaul. The bug was discovered by security researcher Stefan Kanthak, who says the Skype update can be tricked into loading malicious code instead of the right library. An attacker would simply need to put a fake DLL into a user-accessible temporary folder, with the name of an existing DLL that could be modified by anyone without system privileges. Anyone trying to hijack your PC would need access to your file system obviously, but according to Kanthak, once system access is granted, an attacker "can do anything". However, the hacker would require physical access to the computer to do this.

Kanthak told Microsoft about the vulnerability -- which could let hackers steal files, delete data or run ransomware -- back in September, and the company acknowledged a fix would require "a large code revision". Speaking to ZDNet, Kanthak said that even though Microsoft was able to reproduce the issue, a fix will only arrive "in a newer version of the product rather than a security update", the implication being that patching the issue would require too much work. Microsoft said it's put "all resources" into building a new client, but has not revealed when that's likely to land. We've reached out to Microsoft for comment.

Update: A Microsoft spokesperson gave us the following statement. "We have a customer commitment to investigate reported security issues, and proactively update impacted devices as soon as possible. Our standard policy is that on issues of low risk, we remediate that risk via our Update Tuesday schedule.​"

Update 2: This story originally stated that an attacker needs physical access to a PC to take advantage of this flaw. This has been corrected to state the attacker simply needs access to the file system. Wording has also been updated to clarify that Skype is the app being tricked into loading malicious code.

Newsletter

Introducing 'Fronx' - Maruti Suzuki's sporty C-SUV at Ambal Auto's Nexa showroom in Nava India!

The car is designed with a modern aerodynamic style that is both aesthetically pleasing and sporty. The Fronx C-SUV is p...

Hello iPhone: Following EU, Indian Government to make USB-C charging port mandatory across all smartphones

Earlier this year, Greg Joswiak, Senior Vice President, worldwide marketing at Apple said during The Wall Street Journal...

Covid Vaccine 100% Effective On 12-15-Year-Olds: BioNTech-Pfizer

Covid Vaccine 100% Effective On 12-15-Year-Olds: BioNTech-Pfizer

Telegram introduces group voice chat in a unique way to mimic conference calls

Telegram introduces group voice chat in a unique way to mimic conference calls

Coimbatoreans witnessed The Great Conjunction with a telescopic view

The solar system's two biggest planets - Jupiter and Saturn were in a straight plane yesterdayas part of "The Great Conj...

Astronomy Festival on 21 Dec: Discussion on rare event of alignment of Jupiter and Saturn

Astronomy Festival on the 21st: Discussion on the rare event of alignment of Jupiter and Saturn