Sploitus

CVE-2007-0038

27 known exploits for CVE-2007-0038

Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.

Affected products
Windows
Microsoft Windows 2000
All versions
Microsoft Windows 2003 Server
= gold, SP1, SP2
Microsoft Windows Vista
All versions
Microsoft Windows Xp
All versions
CVSS 2.0
9.3 HIGH
EPSS
72.9% (99th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2007-03-30
CVE-2007-0038 at NVD
Authoritative description, scoring and affected products

27 known exploits for CVE-2007-0038

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2007-0038
2026-08-26 KitPloitKITPLOIT
Microsoft Windows - ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP) (MS07-017) (Metasploit)
2010-09-20 MetasploitEXPLOITDBRuby
Microsoft Windows - ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (HTTP) (MS07-017) (Metasploit)
2010-08-12 MetasploitEXPLOITDBRuby
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
2010-07-25 hdm <x@hdm.io>, skape <mmiller@hick.org>METASPLOITRuby
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (HTTP)
2010-04-15 hdm <x@hdm.io>, skape <mmiller@hick.org>, Solar Eclipse <solareclipse@phreedom.org>METASPLOITRuby
Windows ANI LoadAniIcon() Chunk Size Stack Overflow (HTTP)
2010-04-15 H D MoorePACKETSTORMRuby
Windows ANI LoadAniIcon() Chunk Size Stack Overflow (SMTP)
2009-11-26 H D MoorePACKETSTORMRuby
Microsoft Windows - Animated Cursor Stack Overflow
2007-06-07 RISE SecurityEXPLOITDBPython
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
2007-04-26 Lionel d'HauenensEXPLOITDB
Microsoft Windows - GDI Privilege Escalation (MS07-017) (2)
2007-04-17 Lionel d'HauenensEXPLOITDBC
Microsoft Windows - Animated Cursor '.ani' Local Overflow
2007-04-09 Breno Silva PintoEXPLOITDBC
Microsoft Windows - GDI Privilege Escalation (MS07-017) (1)
2007-04-08 Ivanlef0uEXPLOITDBC
Microsoft Windows Explorer - '.ANI' File Denial of Service
2007-04-08 MarsuEXPLOITDBC
Windows Animated Cursor Header buffer overflow
2007-04-05 SAINT CorporationSAINT
Windows Animated Cursor Header buffer overflow
2007-04-05 SAINT CorporationSAINT
Windows Animated Cursor Header buffer overflow
2007-04-05 SAINT CorporationSAINT
Windows Animated Cursor Header buffer overflow
2007-04-05 SAINT CorporationSAINT
Microsoft Windows - Animated Cursor '.ani' Local Overflow (Hardware DEP)
2007-04-03 devcodeEXPLOITDBC
Microsoft Windows - Animated Cursor '.ani' Universal Generator
2007-04-03 YAG KOHHAEXPLOITDB
ani_loadimage_chunksize-email.rb.txt
2007-04-03 Matt MillerPACKETSTORMRuby
ani_loadimage_chunksize-browser.rb.txt
2007-04-03 Matt MillerPACKETSTORMRuby
Microsoft Windows - Animated Cursor '.ani' Local Buffer Overflow
2007-04-02 MarsuEXPLOITDBC
Microsoft Windows - Animated Cursor '.ani' Remote (eeye patch Bypass)
2007-04-01 jamikazuEXPLOITDB
Microsoft Windows XP/Vista - Animated Cursor '.ani' Remote Overflow
2007-04-01 jamikazuEXPLOITDB
Microsoft Windows XP - Animated Cursor '.ani' Remote Overflow (2)
2007-04-01 Trirat PuttaraksaEXPLOITDB
Microsoft Windows - Animated Cursor '.ani' Local Stack Overflow
2007-03-31 devcodeEXPLOITDBC
Immunity Canvas: ANI_CURSOR
2007-03-30 Immunity CanvasCANVAS