User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
The specific flaw exists in Skype's handling of the 'skype-plugin:' protocol. An attacker can specify a malicious URI utlizing the undocumented 'save_pxml' command that upon clicking will trigger the deletion of an arbitrary attacker specified XML file.
Disclosure Timeline:
2009-07-14 - Initial report to vendor, no response.
2010-01-12 - Skype requests more details, specifically a screen shot.
2010-01-19 - We followed up with Skype again who has not been heard from since.
2010-03-11 - Uncoordinated release of public advisory due to failure to communicate, issue remains unresolved.