← Vulnerability feed

Vulnerability record · CVE-2007-0038 · published 30 March 2007

CVE-2007-0038: Microsoft Windows ANI cursor parsing stack buffer overflow

Microsoft · Windows 2000

The animated cursor code in Windows 2000 SP4 through Vista contains a stack-based buffer overflow triggered by a large length value in the second or later anih block of a RIFF .ANI, .cur, or .ico file. Processing such a cursor, animated cursor, or icon corrupts memory, allowing remote code execution or a persistent reboot denial of service. It is a variant of CVE-2005-0416 and may duplicate CVE-2007-1765.

9.3 CVSS 2.0 High EPSS 73% · top 0.6% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
40References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote code execution with complete impact and a very high EPSS score, though the flaw is old and a patch has long existed.

What it is

The animated cursor code in Windows 2000 SP4 through Vista contains a stack-based buffer overflow triggered by a large length value in the second or later anih block of a RIFF .ANI, .cur, or .ico file. Processing such a cursor, animated cursor, or icon corrupts memory, allowing remote code execution or a persistent reboot denial of service. It is a variant of CVE-2005-0416 and may duplicate CVE-2007-1765.

Impact

An attacker can execute arbitrary code in the context of the affected process or crash the system into a persistent reboot loop. Successful exploitation gives full control of confidentiality, integrity, and availability per the CVSS vector.

Attack surface

Reached remotely over the network by delivering a crafted cursor or icon file, originally demonstrated through Internet Explorer 6 and 7. No authentication is required, but the CVSS vector indicates medium attack complexity, implying some precondition such as user interaction to open or render the file.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.7288 (99.4th percentile), and references include vendor advisories and US-CERT alerts consistent with active exploitation at disclosure.

What to do

  • Apply Microsoft security bulletin MS07-017 for the affected Windows versions.
  • Upgrade or retire Windows 2000, XP, and Server 2003 systems that no longer receive security updates.
  • Block or strip .ANI, .CUR, and .ICO attachments and downloads at mail and web gateways where feasible.
  • Disable or restrict rendering of animated cursors and icons in browsers and document viewers.
  • Monitor for unexpected reboots or crashes on unpatched endpoints as a possible exploitation indicator.

Detection

  • Hunt for processes loading or rendering .ANI, .CUR, or .ICO files from email, web, or temp directories.
  • Alert on repeated unexpected system reboots or crashes on unpatched Windows hosts.
  • Inspect network and proxy logs for delivery of cursor or icon files from untrusted sources.
  • Check endpoint patch state against MS07-017 to identify exposed systems.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html
http://secunia.com/advisories/24659 Vendor Advisory
http://securityreason.com/securityalert/2542
http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp Vendor Advisory
http://www.kb.cert.org/vuls/id/191609 US Government Resource
http://www.osvdb.org/33629
http://www.securityfocus.com/archive/1/464269/100/0/threaded
http://www.securityfocus.com/archive/1/464339/100/0/threaded
http://www.securityfocus.com/archive/1/464340/100/0/threaded
http://www.securityfocus.com/archive/1/464342/100/0/threaded
http://www.securityfocus.com/archive/1/464459/100/100/threaded
http://www.securityfocus.com/archive/1/464460/100/100/threaded
http://www.securityfocus.com/archive/1/466186/100/200/threaded
http://www.us-cert.gov/cas/techalerts/TA07-089A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-093A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-100A.html US Government Resource
http://www.vupen.com/english/advisories/2007/1215 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017
https://exchange.xforce.ibmcloud.com/vulnerabilities/33301
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1854
http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html
http://secunia.com/advisories/24659 Vendor Advisory
http://securityreason.com/securityalert/2542
http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp Vendor Advisory
http://www.kb.cert.org/vuls/id/191609 US Government Resource
http://www.osvdb.org/33629
http://www.securityfocus.com/archive/1/464269/100/0/threaded
http://www.securityfocus.com/archive/1/464339/100/0/threaded
http://www.securityfocus.com/archive/1/464340/100/0/threaded
http://www.securityfocus.com/archive/1/464342/100/0/threaded
http://www.securityfocus.com/archive/1/464459/100/100/threaded
http://www.securityfocus.com/archive/1/464460/100/100/threaded
http://www.securityfocus.com/archive/1/466186/100/200/threaded
http://www.us-cert.gov/cas/techalerts/TA07-089A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-093A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA07-100A.html US Government Resource
http://www.vupen.com/english/advisories/2007/1215 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017
https://exchange.xforce.ibmcloud.com/vulnerabilities/33301
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1854

Track CVE-2007-0038 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2016-7256Windows atmfd.dll OpenType Font Remote Code ExecutionThe Windows font library (atmfd.dll) mishandles crafted OpenType fonts, allowing remote code execution. An attacker can host a malicious font on a we…KEVEPSS 65%analysed8.8CVE-2015-2426Windows Adobe Type Manager Library buffer underflow via crafted OpenType fontA buffer underflow in atmfd.dll, the Windows Adobe Type Manager Library, lets a crafted OpenType font trigger memory corruption. Because font parsing…KEVEPSS 87%analysed8.8CVE-2015-2360Microsoft Windows win32k.sys memory corruption privilege escalationwin32k.sys in the Windows kernel-mode drivers mishandles memory, allowing a local user to corrupt memory through a crafted application. The flaw is a…KEVEPSS 15%analysed8.8CVE-2014-6332Windows OLE Automation SafeArrayDimen array redimensioning remote code executionOleAut32.dll in Windows OLE mishandles a size value in the SafeArrayDimen function, allowing an array-redimensioning attempt to corrupt memory. A cra…KEVEPSS 95%analysed8.8CVE-2014-4148Windows win32k.sys TrueType font parsing remote code executionA code injection flaw in the win32k.sys kernel-mode driver lets a crafted TrueType font trigger arbitrary code execution. Because font parsing sits i…KEVEPSS 60%analysed8.8CVE-2014-1812Microsoft Windows Group Policy Preferences credential exposure and privilege escalationGroup Policy Preferences in multiple Windows versions stored and distributed passwords in a way that did not properly protect them, allowing any auth…KEVEPSS 65%analysed8.8CVE-2013-3918Microsoft Windows InformationCardSigninHelper ActiveX out-of-bounds writeThe InformationCardSigninHelper ActiveX control in icardie.dll contains an out-of-bounds write that can be triggered by a crafted web page rendered i…KEVEPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2007-0038), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.