Advertisement






Skype IM Client Password Disclosure Vulnerability.

CVE Category Price Severity
CVE-2019-3103 CWE-200 $5000 High
Author Risk Exploitation Type Date
Unknown High Local 2008-09-21
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2008090044

Below is a copy:

Skype IM Client Password Disclosure Vulnerability.

*Version Affected:*
Skype 3.8 / Previous version can be affected.

*Release Date:*
11 September 2008

*Description:*
The skype client inherits client side password disclosure vulnerability. 
The credentials used to connect to
the required service i.e. username and password is not encrypted 
properly. The credentials can be extracted
in clear text by dumping process memory of the live pidgin process when 
a connection is set. The vulnerability
allows anyone with access to the client system to obtain the username 
and password. Additionally, this
vulnerability could also be exploited by fooling the user to execute 
malicious code which would dump the
memory of the process "skype.exe". The skype uses skype.exe and 
skypepm.exe processes while communicating.
The skype.exe dumps password in clear text.
*
Proof of Concept:

**http://evilfingers.com/advisory/skype_pass_dis_vul.pdf
http://secniche.org/advisory/skype_vul.pdf

<cid:part1.09030909.07070102_at_secniche.org>
Links:
http://secniche.org/advisory.html
http://evilfingers.com/advisory/index.php
*
*Credit:*
Aditya K Sood

*Disclaimer*
The information in the advisory is believed to be accurate at the time 
of publishing based on currently available
information. Use of the information constitutes acceptance for use in an 
AS IS condition. There is no representation
or warranties, either express or implied by or with respect to anything 
in this document, and shall not be liable for
any implied warranties of merchantability or fitness for a particular 
purpose or for any indirect special or consequential damages.


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum