← Vulnerability feed

Vulnerability record · CVE-2007-1765 · published 30 March 2007

CVE-2007-1765: Microsoft Windows ANI cursor parsing memory corruption

Microsoft · Windows 2000

Microsoft Windows 2000 SP4 through Vista mishandles malformed ANI files when processing cursors, animated cursors and icons, causing memory corruption. The record is thin and explicitly notes it may be a duplicate of CVE-2007-0038, so affected version details beyond the listed Windows releases are not reliable.

9.3 CVSS 2.0 High EPSS 55% · top 1.0%
9.3CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote code execution with a 9.3 CVSS score and very high EPSS, but the affected platforms are long out of support and the record may be a duplicate of CVE-2007-0038.

What it is

Microsoft Windows 2000 SP4 through Vista mishandles malformed ANI files when processing cursors, animated cursors and icons, causing memory corruption. The record is thin and explicitly notes it may be a duplicate of CVE-2007-0038, so affected version details beyond the listed Windows releases are not reliable.

Impact

A remote attacker can execute arbitrary code in the context of the affected process or force a persistent reboot denial of service. Successful code execution gives full compromise of the host.

Attack surface

Reached remotely over the network by delivering a malformed ANI file, originally demonstrated through Internet Explorer 6 and 7. No authentication is required, but the CVSS vector indicates medium attack complexity and some user interaction is implied by the browser delivery path.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.546 (98.9th percentile) and references include a vendor advisory and third-party zero-day analysis, indicating active interest and likely public exploit material.

What to do

  • Apply the Microsoft security update associated with advisory 935423 or the patch for CVE-2007-0038, and confirm whether this identifier is a duplicate before tracking separately.
  • Upgrade or retire Windows 2000, XP and Vista systems that no longer receive security updates.
  • Block or strip ANI file content at email and web gateways, and disable rendering of animated cursors where feasible.
  • Restrict Internet Explorer usage and enforce safer browsing configurations on remaining legacy hosts.
  • Segment legacy Windows systems to limit lateral movement if code execution occurs.

Detection

  • Monitor for processes loading or writing ANI files from browser cache, email attachments or temporary directories.
  • Alert on unexpected child processes spawned by iexplore.exe or other applications that render cursors and icons.
  • Hunt for repeated unexpected system reboots on legacy Windows hosts that could indicate the denial of service variant.
  • Review proxy and email logs for ANI file downloads or attachments reaching legacy Windows endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/ Broken Link
http://research.eeye.com/html/alerts/zeroday/20070328.html Third Party Advisory
http://vil.nai.com/vil/content/v_141860.htm Broken Link
http://www.avertlabs.com/research/blog/?p=230 Third Party Advisory
http://www.avertlabs.com/research/blog/?p=233 Third Party Advisory
http://www.microsoft.com/technet/security/advisory/935423.mspx Vendor Advisory
http://www.securityfocus.com/archive/1/464287/100/0/threaded
http://www.securityfocus.com/archive/1/464345/100/0/threaded
http://www.securityfocus.com/bid/23194 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1017827 Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2007/1151 Third Party Advisory
http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/ Broken Link
http://research.eeye.com/html/alerts/zeroday/20070328.html Third Party Advisory
http://vil.nai.com/vil/content/v_141860.htm Broken Link
http://www.avertlabs.com/research/blog/?p=230 Third Party Advisory
http://www.avertlabs.com/research/blog/?p=233 Third Party Advisory
http://www.microsoft.com/technet/security/advisory/935423.mspx Vendor Advisory
http://www.securityfocus.com/archive/1/464287/100/0/threaded
http://www.securityfocus.com/archive/1/464345/100/0/threaded
http://www.securityfocus.com/bid/23194 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1017827 Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2007/1151 Third Party Advisory

Track CVE-2007-1765 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-0219Microsoft internet explorer vulnerabilityMicrosoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, …EPSS 39%10.0CVE-2007-0217Internet Explorer wininet.dll FTP client heap corruptionThe FTP client code in wininet.dll, used by Microsoft Internet Explorer 5.01 and 6, mishandles an FTP server response of a specific length, writing a…EPSS 58%analysed10.0CVE-2006-1186Internet Explorer ActiveX COM object instantiation memory corruptionInternet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code by instantiating the Mdt2gddr.dll, Mdt2dd.dll, and Mdt2gddo.dll CO…EPSS 58%analysed10.0CVE-2004-1050Internet Explorer 6 heap overflow via IFRAME, FRAME and EMBED attributesInternet Explorer 6 contains a heap-based buffer overflow triggered by long SRC or NAME attributes in IFRAME, FRAME and EMBED elements. A remote atta…EPSS 67%analysed10.0CVE-2004-0985Microsoft ie vulnerabilityInternet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file typ…EPSS 20%10.0CVE-2004-0216Internet Explorer Install Engine integer overflow enables remote code executionThe Install Engine (inseng.dll) in Internet Explorer 5.01, 5.5, and 6 contains an integer overflow when calculating a buffer length for a long .CAB f…EPSS 49%analysed10.0CVE-2004-0201Microsoft HTML Help hh.exe heap buffer overflow via crafted CHM fileThe HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large len…EPSS 45%analysed10.0CVE-2004-0212Windows Task Scheduler .job file stack buffer overflowThe Windows Task Scheduler in Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, contains a stack-based buffer overflow triggered by a .…EPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2007-1765), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.