Animated cursor points to trouble for Microsoft

Network Security · 2007

Microsoft was forced to issue an emergency patch for a wide range of operating systems in early April. A zero-day vulnerability targeting its animated cursor code enabled a malformed .ani, cur, or .ico file to cause a stack-based buffer overflow in any operating system from Windows 2000 SP4 through to Windows Vista. In the worst case, the overflow enabled remote attackers to take complete control of a system.

Read the paper · More papers on PaperTik