First published: Fri Mar 30 2007(Updated: )
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Vista | =beta | |
Microsoft Windows Vista | =beta2 | |
Microsoft Windows Vista | =beta1 | |
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp3 | |
Microsoft Windows 2000 | =sp3 | |
Microsoft Windows 2000 | =sp3 | |
Microsoft Windows 2000 | =sp3 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows Vista | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows Server 2003 | ||
Microsoft Windows Server 2003 | ||
Microsoft Windows Server 2003 | ||
Microsoft Windows Server 2003 | ||
Microsoft Windows Vista | ||
Microsoft Windows 2000 | =sp2 | |
Avaya DEFINITY ONE Media Server | ||
Avaya S8100 | ||
Avaya IP600 Media Servers | ||
Microsoft Internet Explorer | =7.0 | |
Avaya S3400 | ||
Internet Explorer | <=6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1765 is considered critical due to its potential to allow remote code execution and cause denial of service through memory corruption.
To mitigate CVE-2007-1765, it is recommended to apply the latest security updates and patches provided by Microsoft for affected Windows versions.
CVE-2007-1765 affects various Windows versions including Windows 2000, Windows XP, and Windows Vista in specific service packs and editions.
CVE-2007-1765 involves vulnerabilities related to memory corruption caused by malformed Animated Cursor (ANI) files.
Yes, an attacker can exploit CVE-2007-1765 remotely by sending a specially crafted ANI file to the vulnerable system.