vendor:
Windows
by:
Marsu
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Windows
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 FR
MS Windows .ANI File Local Buffer Overflow
This exploit is a local buffer overflow in the .ANI file format on Microsoft Windows. It launches calc.exe on various applications such as Word and Winamp. DEP (Data Execution Prevention) needs to be turned off for it to work on Explorer. It was tested against Windows XP SP2 FR.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest security patches and updates provided by Microsoft. Additionally, enabling DEP (Data Execution Prevention) can also help in preventing buffer overflow attacks.