Skype for Windows cross-zone code execution

skype-addvideotochat-code-execution (39754) The risk level is classified as HighHigh Risk

Description:

Skype could allow a remote attacker to bypass cross-zone restrictions and execute arbitrary code on a vulnerable system, caused by the insecure usage of Internet Explorer when loading content from certain Web sites. Script loaded from the Dailymotion or Metacafe Web site will execute in Internet Explorer's Local Zone instead of the Internet Zone. By persuading a victim to perform a search for a video on the Skype video gallery section of one of the affected Web sites, a remote attacker could inject malicious script into the "Add video to chat" or "Add video to mood" dialog using the "Title" or "Description" video metadata field. An attacker could exploit this vulnerability to execute arbitrary code on the victim's system.

*CVSS:

Base Score: 9.3
  Access Vector: Network
  Access Complexity: Medium
  Authentication: None
  Confidentiality Impact: Complete
  Integrity Impact: Complete
  Availability Impact: Complete
 
Temporal Score: 7.3
  Exploitability: Proof-of-Concept
  Remediation Level: Official-Fix
  Report Confidence: Confirmed

Consequences:

Gain Access

Remedy:

Upgrade to the latest version of Skype (3.8 or later), available from the Skype Web site. See References.

References:

  • Aviv Raff On .NET Web site: Skype cross-zone scripting vulnerability.
  • Aviv Raff On .NET Web site: No more videos for you. Come back when patch available!.
  • Full-Disclosure Mailing List, Thu, 17 Jan 2008 09:59:13 +0200: Skype videomood XSS.
  • Skype Web site: Download the latest version of Skype.
  • SKYPE-SB/2008-001: Skype Cross Zone Scripting Vulnerability.
  • BID-27338: Skype Web Content Zone Remote Code Execution Vulnerability
  • CVE-2008-0454: Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the Add video to chat dialog, aka videomood XSS.
  • CVE-2008-0583: Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) Add video to chat or (2) Add video to mood dialog, a different vector than CVE-2008-0454.
  • OSVDB ID: 42863: Skype Internet Explorer Web Control Dailymotion Title Field Cross-zone Scripting
  • OSVDB ID: 42864: Skype Internet Explorer Web Control Video Gallery Metacafe Movie Title Cross-zone Scripting
  • OSVDB ID: 42868: Skype Metacafe Pro Gallery Submitted Movie Multiple Field Cross-zone Scripting
  • US-CERT VU#248184: Skype does not properly filter input from external websites
  • US-CERT VU#794236: SkypeFind fails to properly sanitize user-supplied input

Platforms Affected:

  • Skype Skype for Windows 3.6.0.244

Reported:

Jan 17, 2008

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email ignore thisxforceignore this@ignore thisus.ignore thisibm.comignore this

Return to the main page