CVE-2007-0038
HIGH 9.3EPSS 72.9%
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.
- CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 72.88% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2007-03-30
- Updated
- 2024-08-07
Proof-of-concept exploits (1)
- Axua/CVE-2007-00381★ · 2019-11-29
Metasploit modules (1)
ExploitDB entries (8)
- https://www.exploit-db.com/exploits/16698
- https://www.exploit-db.com/exploits/16526
- https://www.exploit-db.com/exploits/4045
- https://www.exploit-db.com/exploits/3804
- https://www.exploit-db.com/exploits/3755
- https://www.exploit-db.com/exploits/3695
- https://www.exploit-db.com/exploits/3688
- https://www.exploit-db.com/exploits/3684