Risk: Medium
If successfully exploited, a vulnerability reported in Skype may lead to the execution of arbitary code.
The vulnerability is caused due to an error in the URI handler, which can be exploited to bypass the security warning for blacklisted file extensions. This allows an attacker to bypass this security policy and execute arbitrary code.
A user has to be tricked into clicking on a specially crafted URL in order for the attack to be successful.