Vulnerability record · CVE-2017-6517 · published 23 March 2017
CVE-2017-6517: Microsoft Skype DLL search path hijacking allows remote code execution
Microsoft · Skype
Microsoft Skype 7.16.0.102 loads the DLL api-ms-win-core-winrt-string-l1-1-0.dll in an uncontrolled manner, allowing an attacker to place a malicious DLL where the Skype.exe process will load it. Because the DLL is loaded without the user's knowledge, successful exploitation yields arbitrary code execution in the context of Skype. The flaw is a classic uncontrolled search path element (CWE-427) in a widely deployed desktop client.
Description
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 9.8 and a high EPSS percentile indicate severe impact and elevated exploitation likelihood, though the absence of KEV listing and the age of the affected version temper the rating below critical.
What it is
Microsoft Skype 7.16.0.102 loads the DLL api-ms-win-core-winrt-string-l1-1-0.dll in an uncontrolled manner, allowing an attacker to place a malicious DLL where the Skype.exe process will load it. Because the DLL is loaded without the user's knowledge, successful exploitation yields arbitrary code execution in the context of Skype. The flaw is a classic uncontrolled search path element (CWE-427) in a widely deployed desktop client.
Impact
An attacker gains arbitrary code execution on the targeted system with the privileges of the Skype process, enabling malware installation, data theft, or further lateral movement. No user interaction is required beyond the normal operation of the affected application.
Attack surface
The CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no authentication and no user interaction, consistent with a DLL planted in a location the Skype process searches. The record does not specify the exact delivery path or required file placement, so the precise network-to-filesystem mechanism is not detailed.
Exploitation
A public exploit is referenced (Packet Storm DLL Hijacking advisory), and EPSS reports a 30-day exploitation probability of 0.46342 (98.8th percentile), indicating elevated likelihood. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Upgrade Skype to a version later than 7.16.0.102 that resolves the DLL loading issue; consult Microsoft's advisory for the fixed release.
- Apply Microsoft's guidance for the affected Skype build and verify the installed version on all endpoints.
- Restrict write access to directories searched by Skype.exe so unprivileged users cannot plant DLLs there.
- Use application allowlisting or DLL load hardening controls to block unsigned or unexpected DLLs from loading into Skype.
- Monitor for and remove unauthorized copies of api-ms-win-core-winrt-string-l1-1-0.dll from user-writable paths.
Detection
- Hunt for api-ms-win-core-winrt-string-l1-1-0.dll files located outside the legitimate system directories, especially in user-writable or application folders.
- Monitor process creation events where Skype.exe loads DLLs from non-standard paths using Sysmon Event ID 7 (ImageLoad) or equivalent EDR telemetry.
- Alert on unsigned or newly written DLLs appearing in directories adjacent to Skype.exe or in the current working directory.
- Correlate file-write events to Skype-related paths with subsequent Skype.exe process starts to detect DLL planting attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-6517 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6517), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.