Denial of Service in Microsoft Universal Plug and Play Service
A vulnerability exists in Microsoft Universal Plug and Play (UPnP) service that can cause a Denial of Service (DoS) condition.
November 1, 2001
ReportedNovember 1, 2001, by Microsoft.
VERSIONS AFFECTED
All systems running Microsoft’sUniversal Plug and Play, including:
Microsoft Windows XP
Microsoft Windows Me
Microsoft Windows 98 and 98SE
DESCRIPTION
A vulnerability exists in Microsoft Universal Plugand Play (UPnP) service that can cause a Denial of Service (DoS) condition.Because the UPnP service doesn't correctly handle invalid requests or multipleconnections exceeding 1017, an attacker can use the vulnerability to create aDoS condition. The UPnP service is not enabled by default, but an attacker canenable it through the OEM channels. Microsoft recommends that users block ports1900 and 5000 with a firewall.
VENDORRESPONSE
Thevendor, Microsoft, has released securitybulletin MS01-054to address this vulnerability and recommends that affected users apply theappropriate patch provided at one of the URLs given in the bulletin.
CREDIT
Discovered by Kenof Franklin Tech Unlimited.
Read more about:
MicrosoftAbout the Author
You May Also Like