A major bug is forcing Microsoft to rebuild Skype for Windows

移动互联 2018-02-14

Skype has fallen foul of a security flaw that can allow attackers to gain system-level privileges to vulnerable computers, Microsoft has confirmed. However, the company won't immediately fix the issue because doing so would require a complete code overhaul. The bug was discovered by security researcher Stefan Kanthak, who says the Skype update can be nefariously tweaked to trick an application into drawing incorrect code instead of the right library. This would let a hacker download malicious code and put it into a user-accessible temporary folder, renaming it to an existing DLL that could be modified by anyone without system privileges. According to Kanthak, once system access is granted, an attacker "can do anything". However, the hacker would require physical access to the computer to do this.

Engadget

责编内容by:Engadget (源链)。感谢您的支持!

您可能感兴趣的

REVIEW: Microsoft’s newest laptop delivers a... Microsoft Surface Laptop Melia Robinson/Business Insider There's nothing wrong with a good gimmick — sometimes, you hav...
Google Detects Android Spyware That Spies On Whats... In an attempt to protect Android users from malware and shady apps, Google has been continuously working to detect and remove malicious apps from...
微软下月将举行Win10 MR头显现场演示活动... 向消费者兜售VR/MR最好的方式就是充分展示它,现场演示是一种很好的呈现方式。微软就计划下月通过现场演示展示Win10 MR头显。 根据英国一家名为Wave的公司发布的招聘信息推测,微软将举行现场演示活动,展示其Win10 MR头显(包括宏碁、惠普以及戴尔Visor等)。Wave公司正在招...
你真的需要杀毒软件吗?老司机谈电脑裸奔的技巧... 近日,著名杀毒软件卡巴斯基在美国遭遇禁售的消息闹得沸沸扬扬。美国政府以安全为理由,禁止卡巴斯基进入政府软件采购名单。美国认为,卡巴斯基存在所谓的“隐藏后门”,会泄露机密信息。且不说美国的说法是否真实,但从技术的角度来看,杀毒软件的确往往拥有一般软件所没有的的高权限,如果有心泄露机密,是有可能做到的。...
Watch Out, Apple: New Mysterious Microsoft Surface... Microsoft took the wraps off the Surface Pro and the Surface Laptop earlier this year, but it appears that the company still has a few surprises on th...