Categories: Technology

Skype bug could give hackers full control of PC, but Microsoft will not fix it right away

Microsoft has had a bad time last month after the potential threat linked to Spectre and Meltdown, affecting almost all major chip makers including Intel, AMD, and ARM was uncovered. Microsoft issued an update to resolve it but that also went wrong, wrecking some AMD-powered PCs. And now, the software giant is looking forward to resolving another major security flaw in Skype for Windows but it needs more time for that.

Recently, a security researcher Stefan Kanthak has discovered a bug which may cause a Skype update into loading malicious code instead of the right library. The hacker would simply need to put a fake DLL into a user-accessible temporary folder, with the name of an existing DLL that could be modified by anyone without system access. As of now, Microsoft has confirmed that Skype is currently experiencing a security flaw that can endow attackers with system-level access.

However, Microsoft will not immediately fix the issue because doing so would require a complete code revamping. The bug is attributed to the Skype automatic update function which can be altered to trick the application into allocating permissions by inserting incorrect code. According to Kanthak,

“They’ve reviewed the code and were able to reproduce the issue, but have determined that the fix will be implemented in a newer version of the product rather than a security update.”

It appears that Microsoft will not be issuing a security update instead Skype will undergo a major revision later in which the bug will get fixed. According to an official statement by the company,

“We have a customer commitment to investigate reported security issues, and proactively update impacted devices as soon as possible. Our standard policy is that on issues of low risk, we remediate that risk via our Update Tuesday schedule.”

It must be noted that the security flaw is only limited to the full Skype program on the desktop, meaning users of the Universal Windows Platform (UWP) application will face no issues.

Sponsored
Sajeel Syed

I am a writer at TechJuice, overseeing IT, Telecom, Cryptocurrency, and other tech-related features here. When I'm not working, I spend some of my time with good old Xbox 360 and the rest in social activism. Follow me on Twitter: https://twitter.com/sajeelshamsi

Leave a Comment
Share
Published by
Sajeel Syed

Recent Posts

China’s Tencent Releases Large Language Model, Opens it For Enterprise Use

Capable of conversing in both Chinese and English, Tencent’s large language model ‘Hunyuan’ is claimed…

8 months ago

Apple Reportedly Spending ‘Million of Dollars Each Day’ for AI Training

Working on multiple AI models, Apple has allocated several teams who are working on artificial…

8 months ago

World’s Largest Wind Turbine Breaks Record For Power Generated In A Single Day-During A Typhoon

The world's largest offshore wind turbine has achieved a milestone by setting a new record…

8 months ago

YouTube Will Let You Play Mini Games Soon

YouTube is stepping into the world of gaming. YouTube has started testing out its gaming…

8 months ago

Pakistani Student Won First Position In Matric Exams of UAE

In a remarkable academic achievement, Abdullah Zaman, a Pakistani student hailing from Attock, has clinched…

8 months ago

‘Flying Bum’ World’s largest Aircraft Is Ready To Launch In 2026 With Hybrid Technology

Flying Bum, the world's largest aircraft is ready to launch in 2026. The Airlander 10…

8 months ago