vendor:
Windows
by:
Breno Silva Pinto
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Windows
Affected Version From: Windows
Affected Version To: Windows XP SP2
Patch Exists: YES
Related CWE: CVE-2007-0038
CPE: o:microsoft:windows
Platforms Tested: Windows XP SP2 - Portuguese
ANI Exploit
The exploit is a buffer overflow vulnerability in the ANI header parsing code in Microsoft Windows. It allows an attacker to execute arbitrary code on a target system by sending a specially crafted ANI file. The exploit includes a shellcode that creates a port bind shell on port 13579. The exploit has been tested on Windows XP SP2 - Portuguese.
Mitigation:
Apply the relevant security patches provided by Microsoft.