SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#191609

Microsoft Windows animated cursor stack buffer overflow

Overview

Microsoft Windows contains a stack buffer overflow in the handling of animated cursor files. This vulnerability may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.

I. Description

Animated cursor files (.ani) contain animated graphics for icons and cursors. Animated cursor files are stored as Resource Interchange File Format (RIFF) data. A stack buffer overflow vulnerability exists in the way that Microsoft Windows processes malformed animated cursor files. Specifically, Microsoft Windows fails to properly validate the size of animated cursor file headers. Note that Windows Explorer will process animated cursor files with several different file extensions, such as .ani, .cur, or .ico.

Note that animated cursor files are parsed when the containing folder is opened or it is used as a cursor. In addition, Internet Explorer can process animated cursor files in HTML documents, so web pages and HTML email messages can also trigger this vulnerability. Note that any Windows application may call the vulnerable code to process animated cursor files.

More information on this vulnerability is available in Microsoft Security Advisory Bulletin MS07-017.

Exploit code for this vulnerability is publicly available, and it is being actively exploited.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial-of-service condition.

III. Solution

Apply updates from Microsoft

Microsoft has released an update for this vulnerabilitity in Microsoft Security Bulletin MS07-017.

Block access to malformed animated cursor files at network perimeters

By blocking access to malformed animated cursor files using HTTP proxies, mail gateways, and other network filter technologies, system administrators may also limit potential attack vectors.

Please be aware that filtering based just on the ANI, CUR, or ICO file extensions will not block all known attack vectors for this vulnerability. Filter mechanisms should be looking for any file that Microsoft Windows recognizes as an animated cursor file by virtue of its file contents. Animated cursor files begin with the ASCII sequence: RIFF (hex 52 49 46 46). Malformed Animated cursor files that can exploit this vulnerability contain the string anih followed by the dword 0x24, and then a second instance of anih followed by a dword value other than 0x24. Please check with your network vendor for updated signatures.

Configure Outlook to display messages in plain text

An attacker may be able to exploit this vulnerability by convincing a user to display a specially crafted HTML email. This can happen automatically if the preview pane is enabled in your mail client. Configuring Outlook to display email in plain text can help prevent exploitation of this vulnerability through email. Consider the security of fellow Internet users and send email in plain text format when possible.
Note: The Outlook Express option for displaying messages in plain text will not prevent exploitation of this vulnerability. This workaround is only viable for systems with Microsoft Outlook.

Disable email preview pane

By disabling the preview pane in your mail client, incoming email messages will not be automatically rendered. This can help prevent exploitation of this vulnerability.

Configure Windows Explorer to use Windows Classic Folders

When Windows Explorer is configured to use the "Show common tasks in folders" option, HTML within a file may be processed when that file is selected. If the "Show common tasks in folders" is enabled, selecting a specially crafted HTML document in Windows Explorer may trigger this vulnerability. Note that the "Show common tasks in folders" is enabled by default. To mitigate this attack vector, enable the "Use Windows classic folders" option. To enable this option in Windows Explorer:

  • Open Windows Explorer
  • Select Folder Options from the Tools menu
  • Select the "Use Windows classic folders" option in the Tasks section
Do not follow unsolicited links

In order to convince users to visit their sites, attackers often use URL encoding, IP address variations, long URLs, intentional misspellings, and other techniques to create misleading links. Do not click on unsolicited links received in email, instant messages, web forums, or internet relay chat (IRC) channels. Type URLs directly into the browser to avoid these misleading links. While these are generally good security practices, following these behaviors will not prevent exploitation of this vulnerability in all cases, particularly if a trusted site has been compromised or allows cross-site scripting.

Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable3-Apr-2007

References

http://www.us-cert.gov/cas/techalerts/TA07-089A.html
http://www.us-cert.gov/cas/techalerts/TA07-093A.html
http://www.microsoft.com/technet/security/bulletin/ms07-017.mspx
http://blogs.technet.com/msrc/search.aspx?q=935423
http://www.microsoft.com/technet/security/advisory/935423.mspx
http://www.determina.com/security.research/vulnerabilities/ani-header.html
http://vil.nai.com/vil/content/v_141860.htm
http://www.avertlabs.com/research/blog/?p=230
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FANICMOO%2EAX&VSect=T
http://secunia.com/advisories/24659/
http://research.eeye.com/html/alerts/zeroday/20070328.html
http://xforce.iss.net/xforce/alerts/id/258

Credit

This vulnerability was reported by Alexander Sotirov of Determina.

This document was written by Jeff Gennari and Will Dormann.

Other Information

Date Public:2007-03-29
Date First Published:2007-03-29
Date Last Updated:2007-08-15
CERT Advisory: 
CVE-ID(s):CVE-2007-0038
NVD-ID(s):CVE-2007-0038
US-CERT Technical Alerts: 
Metric:142.50
Document Revision:51

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader