Vulnerability record · CVE-2007-1765 · published 30 March 2007
CVE-2007-1765: Microsoft Windows ANI cursor parsing memory corruption
Microsoft · Windows 2000
Microsoft Windows 2000 SP4 through Vista mishandles malformed ANI files when processing cursors, animated cursors and icons, causing memory corruption. The record is thin and explicitly notes it may be a duplicate of CVE-2007-0038, so affected version details beyond the listed Windows releases are not reliable.
Description
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with a 9.3 CVSS score and very high EPSS, but the affected platforms are long out of support and the record may be a duplicate of CVE-2007-0038.
What it is
Microsoft Windows 2000 SP4 through Vista mishandles malformed ANI files when processing cursors, animated cursors and icons, causing memory corruption. The record is thin and explicitly notes it may be a duplicate of CVE-2007-0038, so affected version details beyond the listed Windows releases are not reliable.
Impact
A remote attacker can execute arbitrary code in the context of the affected process or force a persistent reboot denial of service. Successful code execution gives full compromise of the host.
Attack surface
Reached remotely over the network by delivering a malformed ANI file, originally demonstrated through Internet Explorer 6 and 7. No authentication is required, but the CVSS vector indicates medium attack complexity and some user interaction is implied by the browser delivery path.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.546 (98.9th percentile) and references include a vendor advisory and third-party zero-day analysis, indicating active interest and likely public exploit material.
What to do
- Apply the Microsoft security update associated with advisory 935423 or the patch for CVE-2007-0038, and confirm whether this identifier is a duplicate before tracking separately.
- Upgrade or retire Windows 2000, XP and Vista systems that no longer receive security updates.
- Block or strip ANI file content at email and web gateways, and disable rendering of animated cursors where feasible.
- Restrict Internet Explorer usage and enforce safer browsing configurations on remaining legacy hosts.
- Segment legacy Windows systems to limit lateral movement if code execution occurs.
Detection
- Monitor for processes loading or writing ANI files from browser cache, email attachments or temporary directories.
- Alert on unexpected child processes spawned by iexplore.exe or other applications that render cursors and icons.
- Hunt for repeated unexpected system reboots on legacy Windows hosts that could indicate the denial of service variant.
- Review proxy and email logs for ANI file downloads or attachments reaching legacy Windows endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1765 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1765), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.