Researcher discovers security flaw with Skype

Security researcher Aviv Raff has discovered and demonstrated a flaw within Skype that allows malicious code to be run under certain circumstances. The problem is caused by Skype’s web control. The program uses Internet Explorer to render internal and external HTML, but does so using “Local Zone” security settings.

Actually taking advantage of the bug would require malware authors to find a trusted site with a cross-zone scripting error. These types of errors are relatively common, and allow for the execution of potentially unsafe scripts as if they carried higher permissions than they actually do. Such scripts have a wide variety of potential applications (some of which might be picked up by other security features, such as Vista’s UAC), but a wide range of potential activity could go completely unblocked and unnoticed. (link)

Advertisements

0 Responses to “Researcher discovers security flaw with Skype”



  1. Leave a Comment

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s




Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 29 other followers

Technorati – Blog Search

Add to Technorati Favorites

submit express


%d bloggers like this: