Vulnerability record · CVE-2007-0038 · published 30 March 2007
CVE-2007-0038: Microsoft Windows ANI cursor parsing stack buffer overflow
Microsoft · Windows 2000
The animated cursor code in Windows 2000 SP4 through Vista contains a stack-based buffer overflow triggered by a large length value in the second or later anih block of a RIFF .ANI, .cur, or .ico file. Processing such a cursor, animated cursor, or icon corrupts memory, allowing remote code execution or a persistent reboot denial of service. It is a variant of CVE-2005-0416 and may duplicate CVE-2007-1765.
Description
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with complete impact and a very high EPSS score, though the flaw is old and a patch has long existed.
What it is
The animated cursor code in Windows 2000 SP4 through Vista contains a stack-based buffer overflow triggered by a large length value in the second or later anih block of a RIFF .ANI, .cur, or .ico file. Processing such a cursor, animated cursor, or icon corrupts memory, allowing remote code execution or a persistent reboot denial of service. It is a variant of CVE-2005-0416 and may duplicate CVE-2007-1765.
Impact
An attacker can execute arbitrary code in the context of the affected process or crash the system into a persistent reboot loop. Successful exploitation gives full control of confidentiality, integrity, and availability per the CVSS vector.
Attack surface
Reached remotely over the network by delivering a crafted cursor or icon file, originally demonstrated through Internet Explorer 6 and 7. No authentication is required, but the CVSS vector indicates medium attack complexity, implying some precondition such as user interaction to open or render the file.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.7288 (99.4th percentile), and references include vendor advisories and US-CERT alerts consistent with active exploitation at disclosure.
What to do
- Apply Microsoft security bulletin MS07-017 for the affected Windows versions.
- Upgrade or retire Windows 2000, XP, and Server 2003 systems that no longer receive security updates.
- Block or strip .ANI, .CUR, and .ICO attachments and downloads at mail and web gateways where feasible.
- Disable or restrict rendering of animated cursors and icons in browsers and document viewers.
- Monitor for unexpected reboots or crashes on unpatched endpoints as a possible exploitation indicator.
Detection
- Hunt for processes loading or rendering .ANI, .CUR, or .ICO files from email, web, or temp directories.
- Alert on repeated unexpected system reboots or crashes on unpatched Windows hosts.
- Inspect network and proxy logs for delivery of cursor or icon files from untrusted sources.
- Check endpoint patch state against MS07-017 to identify exposed systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0038 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0038), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.