Windows XP/Vista (.ANI) Remote Exploit

A security researcher by the name of “jamikazu” has released a PoC exploit for the .ANI cursor flaw. This exploit works on a fully patched Windows Vista machine, and also bypasses eEye’s .ANI patch. I think its kind of funny to see Vista get ruined by this cursor flaw which Microsoft has known about for over 5 months. Below is an excerpt from the site:

Now there is a many thirth patch available for Animated Cursor Handling and with ani checker you can check your system for these patchs. This program checks your system against the (.ANI) vulnerability. It does not do anything harmful to your computer and does not alter any files on it.”

Source: jamikazu.110mb.com

1 Comment »

  1. cad Said,

    April 3, 2007 @ 2:43 am

    On Windows Vista ANI flaw is not dangerous because IE7 Protected mode and low privileges with UAC

RSS feed for comments on this post · TrackBack URI

Leave a Comment