Windows animated cursor overflow (CVE-2007-0038)
Description
Microsoft Windows has a vulnerability in handling of certain graphic files, such as animated cursors. A specially crafted animated cursor can cause Windows to execute arbitrary code.
This vulnerability can be exploited by a web page that includes a specially crafted animated cursor.
This is an arbitrary code execution vulnerability. It means that it can be used to place a backdoor, a virus or spyware on the vulnerable computer.
Recommendations
If you are using Microsoft Windows we recommend using
Windows Update to correct this problem. See also
Microsoft Security Bulletin MS07-017 for information about the patch for this problem.
If you are not using Microsoft Windows, this result is most probably a false positive. Try running
the test for this vulnerability again. If your browser does not crash during the test for this vulnerability, it is not vulnerable.
References