Risk: High
A vulnerability identified in Skype may compromise a user's system if exploited by malicious people.
The vulnerability occurs within the "skype4com" URI handler, due to a boundary error in Skype4COM.dll. This can be exploited to cause a limited heap-based buffer overflow using the supplied URL.
The attacker may be able to execute arbitrary code if a user is tricked into visiting a malicious website.
The vulnerability is confirmed in Skype 3.5.0.239. Other versions prior to 3.6.0.216 may also be affected.