vendor:
Windows Vista
by:
jamikazu
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Windows Vista
Affected Version From: Windows Vista
Affected Version To: Windows Vista
Patch Exists: NO
Related CWE: CVE-2007-0038
CPE: o:microsoft:windows_vista
Platforms Tested: Windows Vista, Windows XP SP2
2007
Windows Animated Cursor Handling Exploit (0day) (Version3)
This exploit targets the Windows Animated Cursor Handling vulnerability in fully patched Windows Vista. It allows for remote code execution and is considered the first real exploit of its kind on Vista. The exploit has been tested on various Windows versions, including Windows Vista Enterprise Version 6.0 (Build 6000) and Windows Vista Ultimate Version 6.0 (Build 6000) with default installations and UAC enabled. It may also work on other NT-based Windows versions, although further testing is needed. The exploit bypasses the eeye security ani patch.
Mitigation:
Apply the latest security patches and updates from Microsoft. Disable the Windows Animated Cursor feature if not required.