CVE-2017-9948

Description

A stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of remote RDP clipboard content within the message box.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
4.865

Associated Vulnerability

VulnerabilityOS Platform
update skype 7.36 to latest versionWindows
update skype 7.36 to latest version (For Ubuntu)Linux
update skype 7.36 to latest version (For Debian)Linux
update skype 7.36 to latest version (For Centos)Linux
update skype 7.36 to latest version (For RedHat)Linux
update skype 7.36 to latest version (For Suse)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343283Skype (8.133.0.202) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234