Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (MS05-002)
| Attack ID: | CPAI-2005-06 | ||||||||||
| Publish Date: | |||||||||||
| Last Update: | |||||||||||
| Category: | Microsoft Windows | ||||||||||
| Vulnerable Systems: | Microsoft Windows NT Server Service Pack 6a Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 Microsoft Windows 2000 Service Pack 3 & Service Pack 4 Microsoft Windows XP Service Pack 1 Microsoft Windows XP 64-Bit Edition Service Pack 1 Microsoft Windows Server 2003 Microsoft Windows Server 2003 64-Bit Edition |
||||||||||
| Source: |
Microsoft Security Bulletin MS05-002 |
||||||||||
| Description: | A vulnerability exists in the way that the Windows Animated Cursors (ANI) are handled. Animated cursors are animated mouse pointers stored in .ani files that can replace the default arrow cursor under Microsoft Windows. A remote attacker could exploit this vulnerability by sending a specially crafted cursor or icon file to a victim as an email attachment or hosting the malicious file on a Web page. This may cause the target system to execute malicious code. Microsoft Windows XP Service Pack 2 is not vulnerable to this issue. |
||||||||||
| Severity: | |||||||||||
| Details: | The .ani file format is used for reading and storing Windows Animated Cursors (animated mouse pointer). A .ani file is a structured format ( Microsoft RIFF) that contains information about the animation (author, title, steps etc) followed by several frames stored in the icon format. |
||||||||||
| Attack Detection: | Using SmartView Tracker, users of VPN-1 NG with Application Intelligence R55W and InterSpect who have performed the Update outlined below, will be able to identify this attack by the following logging entries: Attack Name: ANI Content Protection Violation |
||||||||||
| Solution: | Users of VPN-1 NG with Application Intelligence R54, R55, and InterSpect should update their SmartDefense by clicking the Update Now button on the SmartDefense SmartDashboard General window. Users of VPN-1 NG with Application Intelligence R55W should update their SmartDefense by clicking the Online Update button on the SmartDefense SmartDashboard General window.
To enable the protection: 1. On the SmartDefense navigation tree, select Application Intelligence > Content Protection >Malformed ANI file.
|
||||||||||
| Industry Reference: | CAN-2004-1049 CAN-2004-1305 |
||||||||||
| Additional Information: | In June 6 2005 the malformed ANI protection was updated. | ||||||||||