vendor:
Internet Explorer
by:
Yag Kohha
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 6.x-7.x
Affected Version To: Internet Explorer 6.x-7.x
Patch Exists: YES
Related CWE: CVE-2007-0038
CPE: a:microsoft:internet_explorer
Platforms Tested: Windows XP SP2, Windows Vista
2007
.ANI (RIFF Cursors) 2007 universal exploit generator
This exploit allows an attacker to execute arbitrary code on a target system by exploiting a vulnerability in the way Microsoft Internet Explorer handles .ANI (RIFF Cursors) files. It was tested on MS Internet Explorer 6.x-7.x on Windows XP SP2 and Windows Vista.
Mitigation:
Apply the latest security updates from Microsoft to patch the vulnerability. Disable the loading of .ANI files in Internet Explorer.