Microsoft Windows Kernel ANI File Parsing Crash and DOS Vulnerability

Vulnerable:  Windows NT, Windows 2000 SP0, Windows 2000 SP1, Windows 2000 SP2, Windows 2000 SP3, Windows 2000 SP4, Windows XP SP0, Windows XP SP1, Windows 2003

Not vulnerable:  Windows XP SP2

Parsing a specially crafted ANI file causes the windows kernel to crash or stop to work properly. An attacker can crash or freeze a target system if he sends a specially crafted ANI file within an HTML page or within an Email.

More info in http://www.securityfocus.com/archive/1/385340/2004-12-20/2004-12-26/0

Leave a Reply