An attacker who constructs a Skype URL that is malformed in aspecific way can initiate the transfer of a single named file from one Skype user to another, provided that the sender follows the malicious link and that the recipient has previously authorized the sender.
Skype notes that:
This behavior is due to incorrect parsing of the parameters passed by the URI handler. The vulnerability depends on several factors,including host configuration and the authorization relationship of the sender and the receiver.
The vulnerability isn't easily triggered, but sounds like one that if an attacker would know how to trigger it, wouldn't be that difficult to pull off.
The Alert continues to note:
The attack requires the targeted user to manually follow a specially crafted malformed link, such as on a web page. Depending on several factors, doing so may result in the initiation of a file transfer, which will be accompanied by the normal Skype file transfer dialogue box. If a file transfer is started, it will be visible to the user and may be cancelled by the sender by selecting "Cancel" in the normal way.