News 2 min read

Huge Skype vulnerability will not be fixed by Microsoft any time soon

5 minutes Microsoft cannot fix Skype bug without huge code revision Skype vulnerability not fixed Cybersecurity analysts report about Skype vulnerability which allows hackers to gain access to computer's system account. The bug resides in application's automatic update feature and would require a massive code rewrite which is not only time-consuming but expensive as well. […]

Skype vulnerability not fixed
0 Comments
5 minutes

Microsoft cannot fix Skype bug without huge code revision

Skype vulnerability not fixed
Skype vulnerability not fixed

Cybersecurity analysts report about Skype vulnerability which allows hackers to gain access to computer's system account. The bug resides in application's automatic update feature and would require a massive code rewrite which is not only time-consuming but expensive as well. Likewise, it is more likely that Microsoft will need to issue a new version of Skype rather than simply patch the bug.

According to Stefan Kanthak, a security researcher says that the vulnerability which is present in Skype's update service could be exploited to get full access to the user's chat. This puts the privacy of Skype users at risk since not only private information could be exposed but also misused for phishing purposes or blackmail. Now crooks are more motivated than ever to update Skype virus.

DLL hijacking technique helps criminals exploit the vulnerability

The technique called DLL hijacking refers to the replacement of legitimate Microsoft library with the malicious one. An attacker needs to infiltrate the malicious DLL file onto victim's computer and rename it exactly the same as the original one. This way, the application would search for the library and find malicious DLL file first.

Every time Skype launches it checks for updates automatically. Once it ran the updater, it would use a different executable file and which is precisely vulnerable to DLL hijacking. Even though some criminals might struggle to drop the malicious DLL file on the targeted computer, there are many ways how it may be done.

While sending spam emails with infected attachments or loading DLL through shady websites is an option, IT specialist explains that there is an easier way — a malicious script or malware could remotely transfer DLL file into a temporary folder as well.

Microsoft chose to release a new version of Skype rather than a simple patch

Microsoft has confirmed that fixing the bug was possible. However, the software giant pointed out that it would require too much work. Researcher specified the nature of the work as a huge code revision to fix the bug which would be time-consuming.

However, Microsoft said that it's releasing an update anyway which will now be accompanied by a new version of Skype. It is evident that the company is not going to eliminate the vulnerability despite the fact that users are currently at risk. It means that criminals still have a chance to steal and delete data or infiltrate ransomware on the targeted Windows computers. 

Did this fix work for you?
Gabriel E. Hall

Written by

Malware Removal Expert
Malware removal Ransomware recovery Browser hijackers Spyware analysis Security tools testing

Gabriel E. Hall is a malware removal expert and cybersecurity researcher with over ten years of hands-on experience analysing threats and writing removal guides. She has documented hundreds of malware families — from browser hijackers and adware to ransomware and rootkits — providing step-by-step cleanup instructions tested against real infections. Gabriel's work combines deep technical analysis with clear, actionable language that readers without a security background can follow. Her guides consistently appear among the most-referenced resources for malware removal on Windows systems.

0 Comments

Be the first to comment

Still worried? Run a free check.

Paste any URL or domain — we'll scan it against 4.2M known threats in 10 seconds.

View full scanner → Add to your website →