Security expert Benjamin Kunz-Mejri from security firm Vulnerability Lab discovered a remote zero-day stack buffer overflow vulnerability in Skype. The flaw resides in Skype Web messaging and call service and could be exploited during a team conference call. Microsoft released a patch on 8 June in Skype version 7.37.178. The issue affects the `MSFTEDIT.DLL` dynamic link library of the windows8 (x86) operating system. The vulnerability is located in the print clipboard format & cache transmit via remote session on Windows XP, Windows 7, Windows 8 and Windows 10. An attacker can craft a malicious image file and then copy and paste it from a clipboard into a conversation window in the Skype software.”]
Source: https://securityaffairs.co/wordpress/60507/hacking/skype-buffer-overflow.html

