vendor:
Windows
by:
devcode
7.5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: Windows
Affected Version From: Microsoft Windows 2000 Service Pack 4
Affected Version To: Microsoft Windows Vista
Patch Exists: NO
Related CWE: CVE-2007-1765
CPE: o:microsoft:windows
Platforms Tested:
2007
Windows .ANI LoadAniIcon Stack Overflow
A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to take complete control of an affected system. This issue is due to a stack overflow error within the "LoadAniIcon()" [user32.dll] function when rendering cursors, animated cursors or icons with a malformed header, which could be exploited by remote attackers to execute arbitrary commands by tricking a user into visiting a malicious web page or viewing an email message containing a specially crafted ANI file.
Mitigation:
None as of this time.