Executive Summary

Informations
Name CVE-2007-0038 First vendor Publication 2007-03-30
Vendor Cve Last vendor Modification 2018-10-16

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0038

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:1854
 
Oval ID: oval:org.mitre.oval:def:1854
Title: Windows Animated Cursor Remote Code Execution Vulnerability
Description: Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.
Family: windows Class: vulnerability
Reference(s): CVE-2007-0038
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 1
Os 8
Os 2
Os 3

SAINT Exploits

Description Link
Windows Animated Cursor Header buffer overflow More info here

ExploitDB Exploits

id Description
2010-09-20 Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
2010-08-12 Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (HTTP)
2007-04-26 MS Windows (.ANI) GDI Remote Elevation of Privilege Exploit (MS07-017)
2007-04-17 MS Windows GDI - Local Privilege Escalation Exploit (MS07-017) (2)
2007-04-08 MS Windows GDI - Local Privilege Escalation Exploit (MS07-017)

OpenVAS Exploits

Date Description
2011-01-14 Name : Vulnerabilities in GDI Could Allow Remote Code Execution (925902)
File : nvt/gb_ms07-017.nasl
2010-07-08 Name : Microsoft Windows GDI Multiple Vulnerabilities (925902)
File : nvt/ms07-017.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
33629 Microsoft IE Animated Cursor (.ani) Handling Arbitrary Command Execution

A remote overflow exists in Microsoft Internet Explorer. The browser fails to check the buffer on animated cursors and icons resulting in a stack buffer overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of integrity.

Information Assurance Vulnerability Management (IAVM)

Date Description
2007-04-03 IAVM : 2007-A-0020 - Multiple Vulnerabilities in Microsoft Windows GDI
Severity : Category I - VMSKEY : V0013883

Snort® IPS/IDS

Date Description
2014-01-10 Microsoft Internet Explorer ANI file parsing buffer overflow attempt
RuleID : 3079-community - Revision : 25 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer ANI file parsing buffer overflow attempt
RuleID : 3079 - Revision : 25 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer ani file processing - remote code execution attempt
RuleID : 19886 - Revision : 5 - Type : BROWSER-IE

Nessus® Vulnerability Scanner

Date Description
2007-04-03 Name : Arbitrary code can be executed on the remote host through the email client or...
File : smb_nt_ms07-017.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BUGTRAQ http://www.securityfocus.com/archive/1/464269/100/0/threaded
http://www.securityfocus.com/archive/1/464339/100/0/threaded
http://www.securityfocus.com/archive/1/464340/100/0/threaded
http://www.securityfocus.com/archive/1/464342/100/0/threaded
http://www.securityfocus.com/archive/1/464459/100/100/threaded
http://www.securityfocus.com/archive/1/464460/100/100/threaded
CERT http://www.us-cert.gov/cas/techalerts/TA07-089A.html
http://www.us-cert.gov/cas/techalerts/TA07-093A.html
http://www.us-cert.gov/cas/techalerts/TA07-100A.html
CERT-VN http://www.kb.cert.org/vuls/id/191609
FULLDISC http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html
HP http://www.securityfocus.com/archive/1/466186/100/200/threaded
MISC http://www.determina.com/security_center/security_advisories/securityadvisory...
MS https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07...
OSVDB http://www.osvdb.org/33629
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
SECUNIA http://secunia.com/advisories/24659
SREASON http://securityreason.com/securityalert/2542
VUPEN http://www.vupen.com/english/advisories/2007/1215
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/33301

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
Date Informations
2021-05-04 12:05:10
  • Multiple Updates
2021-04-22 01:05:44
  • Multiple Updates
2020-05-23 13:16:48
  • Multiple Updates
2020-05-23 00:19:03
  • Multiple Updates
2018-10-16 21:19:45
  • Multiple Updates
2018-10-13 00:22:36
  • Multiple Updates
2018-05-03 09:19:27
  • Multiple Updates
2017-10-11 09:23:49
  • Multiple Updates
2017-07-29 12:01:55
  • Multiple Updates
2016-06-28 16:03:15
  • Multiple Updates
2016-04-26 15:35:28
  • Multiple Updates
2014-02-17 10:38:28
  • Multiple Updates
2014-01-19 21:23:45
  • Multiple Updates
2013-11-11 12:37:38
  • Multiple Updates
2013-05-11 00:39:48
  • Multiple Updates
2012-11-07 00:14:23
  • Multiple Updates