Remote exploitation of a security policy bypass in Windows Skype versions could allow an attacker to execute arbitrary code.

Skype has fixed the vulnerability in version 3.8.0.139


Full information at

http://www.skype.com/security/skype-sb-2008-003.html