← Vulnerability feed

Vulnerability record · CVE-2017-6517 · published 23 March 2017

CVE-2017-6517: Microsoft Skype DLL search path hijacking allows remote code execution

Microsoft · Skype

Microsoft Skype 7.16.0.102 loads the DLL api-ms-win-core-winrt-string-l1-1-0.dll in an uncontrolled manner, allowing an attacker to place a malicious DLL where the Skype.exe process will load it. Because the DLL is loaded without the user's knowledge, successful exploitation yields arbitrary code execution in the context of Skype. The flaw is a classic uncontrolled search path element (CWE-427) in a widely deployed desktop client.

9.8 CVSS 3.0 Critical EPSS 46% · top 1.2% CWE-427 · Uncontrolled search path element
9.8CVSS 3.0 base score, v2 10.0
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 9.8 and a high EPSS percentile indicate severe impact and elevated exploitation likelihood, though the absence of KEV listing and the age of the affected version temper the rating below critical.

What it is

Microsoft Skype 7.16.0.102 loads the DLL api-ms-win-core-winrt-string-l1-1-0.dll in an uncontrolled manner, allowing an attacker to place a malicious DLL where the Skype.exe process will load it. Because the DLL is loaded without the user's knowledge, successful exploitation yields arbitrary code execution in the context of Skype. The flaw is a classic uncontrolled search path element (CWE-427) in a widely deployed desktop client.

Impact

An attacker gains arbitrary code execution on the targeted system with the privileges of the Skype process, enabling malware installation, data theft, or further lateral movement. No user interaction is required beyond the normal operation of the affected application.

Attack surface

The CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no authentication and no user interaction, consistent with a DLL planted in a location the Skype process searches. The record does not specify the exact delivery path or required file placement, so the precise network-to-filesystem mechanism is not detailed.

Exploitation

A public exploit is referenced (Packet Storm DLL Hijacking advisory), and EPSS reports a 30-day exploitation probability of 0.46342 (98.8th percentile), indicating elevated likelihood. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.

What to do

  • Upgrade Skype to a version later than 7.16.0.102 that resolves the DLL loading issue; consult Microsoft's advisory for the fixed release.
  • Apply Microsoft's guidance for the affected Skype build and verify the installed version on all endpoints.
  • Restrict write access to directories searched by Skype.exe so unprivileged users cannot plant DLLs there.
  • Use application allowlisting or DLL load hardening controls to block unsigned or unexpected DLLs from loading into Skype.
  • Monitor for and remove unauthorized copies of api-ms-win-core-winrt-string-l1-1-0.dll from user-writable paths.

Detection

  • Hunt for api-ms-win-core-winrt-string-l1-1-0.dll files located outside the legitimate system directories, especially in user-writable or application folders.
  • Monitor process creation events where Skype.exe loads DLLs from non-standard paths using Sysmon Event ID 7 (ImageLoad) or equivalent EDR telemetry.
  • Alert on unsigned or newly written DLLs appearing in directories adjacent to Skype.exe or in the current working directory.
  • Correlate file-write events to Skype-related paths with subsequent Skype.exe process starts to detect DLL planting attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6517 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-9948Microsoft skype memory buffer overflow vulnerabilityA stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of r…EPSS 6.4%7.8CVE-2018-0594Microsoft skype untrusted search path vulnerabilityUntrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.EPSS 5.5%7.8CVE-2018-0595Microsoft skype untrusted search path vulnerabilityUntrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecif…EPSS 5.5%7.8CVE-2016-5720Microsoft skype permissions and access controls vulnerabilityMultiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a…EPSS 1.9%5.9CVE-2019-0932Microsoft skype vulnerabilityAn information disclosure vulnerability exists in Skype for Android, aka 'Skype for Android Information Disclosure Vulnerability'.EPSS 4.9%4.6CVE-2019-0622Microsoft skype improper authentication vulnerabilityAn elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Andro…EPSS 2.0%3.3CVE-2020-24003Microsoft skype vulnerabilityMicrosoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) …EPSS 1.2%7.8CVE-2020-3433Cisco AnyConnect Windows client DLL hijacking via IPC channelCisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through …KEVEPSS 10%analysed

Source: NIST National Vulnerability Database (record CVE-2017-6517), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.