Skype for Windows cross-zone code execution

skype-addvideotochat-code-execution (39754) The risk level is classified as HighHigh Risk

Description:

Skype could allow a remote attacker to bypass cross-zone restrictions and execute arbitrary code on a vulnerable system, caused by the insecure usage of Internet Explorer when loading content from certain Web sites. Script loaded from the Dailymotion or Metacafe Web site will execute in Internet Explorer's Local Zone instead of the Internet Zone. By persuading a victim to perform a search for a video on the Skype video gallery section of one of the affected Web sites, a remote attacker could inject malicious script into the "Add video to chat" or "Add video to mood" dialog using the "Title" or "Description" video metadata field. An attacker could exploit this vulnerability to execute arbitrary code on the victim's system.

Platforms Affected:

  • Skype, Skype for Windows 3.6.0.244

Remedy:

Upgrade to the latest version of Skype (3.8 or later), available from the Skype Web site. See References.

Consequences:

Gain Access

References:

  • Aviv Raff On .NET Web site, Skype cross-zone scripting vulnerability at http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx.
  • Aviv Raff On .NET Web site, No more videos for you. Come back when patch available! at http://aviv.raffon.net/2008/01/22/NoMoreVideosForYouComeBackWhenPatchAvailable.aspx.
  • Full-Disclosure Mailing List, Thu, 17 Jan 2008 09:59:13 +0200, Skype videomood XSS at http://seclists.org/fulldisclosure/2008/Jan/0328.html.
  • Skype Web site, Download the latest version of Skype at http://www.skype.com/download/skype/windows/.
  • SKYPE-SB/2008-001, Skype Cross Zone Scripting Vulnerability at http://skype.com/security/skype-sb-2008-001.html.
  • BID-27338: Skype Web Content Zone Remote Code Execution Vulnerability
  • CVE-2008-0454: Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the Add video to chat dialog, aka videomood XSS.
  • CVE-2008-0583: Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) Add video to chat or (2) Add video to mood dialog, a different vector than CVE-2008-0454.
  • US-CERT VU#248184: Skype does not properly filter input from external websites
  • US-CERT VU#794236: SkypeFind fails to properly sanitize user-supplied input
  • VUPEN/ADV-2008-0194: Skype Video Gallery Browser Cross Zone Scripting Vulnerabilities

Reported:

Jan 17, 2008

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page