Monday, January 28, 2008

Skype flaw allows hackers to turn videos into weapons

A programming error in eBay's Skype communications software could give cyber-criminals a new way to sneak their malicious software onto a victim's PC.

The flaw, which was reported Thursday by security researcher Aviv Raff, has to do with the way that Skype makes use of a Windows Internet Explorer component to render HTML.

Because Skype does not apply strict security controls to the software, an attacker could run scripting code on the victim's system in a dangerous fashion and ultimately install malicious software.

No comments: