CVE-2016-5720: Microsoft Skype

High severity, CVSS 7.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) msi.dll, (2) dpapi.dll, or (3) cryptui.dll that is located in the current working directory.

Affected products

  • Microsoft Skype: affected versions not specified

Published 2017-01-23. Last modified 2026-06-17.