I'm thinking that an attacker with write access to %systemroot% probably has juicier, simpler targets to attack (which potentially let them run code in a higher security context) than animated cursors.

I'm struggling to see what direct relevance this has to what I just said...

