Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-0416

5 documents4 sources
Severity
7.5HIGH
EPSS
66.6%
top 1.46%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 27
Latest updateMay 1

Description

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer overflow.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m474-8gfh-hw6q: The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers2022-05-01
CVEList
CVE-2005-0416: The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers2005-02-14

💥Exploits & PoCs

2
Exploit-DB
Microsoft Internet Explorer - '.ANI' Downloader (MS05-002)2005-01-24
Exploit-DB
Microsoft Internet Explorer - '.ANI' Universal (MS05-002)2005-01-22
CVE-2005-0416 (HIGH CVSS 7.5) | The Windows Animated Cursor (ANI) c | cvebase.io