Denial of Service in Microsoft Universal Plug and Play Service

A vulnerability exists in Microsoft Universal Plug and Play (UPnP) service that can cause a Denial of Service (DoS) condition.

Ken Pfeil

November 1, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedNovember 1, 2001, by Microsoft.

VERSIONS AFFECTED

All systems running Microsoft’sUniversal Plug and Play, including:

  • Microsoft Windows XP

  • Microsoft Windows Me

  • Microsoft Windows 98 and 98SE

 

DESCRIPTION
A vulnerability exists in Microsoft Universal Plugand Play (UPnP) service that can cause a Denial of Service (DoS) condition.Because the UPnP service doesn't correctly handle invalid requests or multipleconnections exceeding 1017, an attacker can use the vulnerability to create aDoS condition. The UPnP service is not enabled by default, but an attacker canenable it through the OEM channels. Microsoft recommends that users block ports1900 and 5000 with a firewall.

 

VENDORRESPONSE

Thevendor, Microsoft, has released securitybulletin MS01-054to address this vulnerability and recommends that affected users apply theappropriate patch provided at one of the URLs given in the bulletin.

 

CREDIT
Discovered by Kenof Franklin Tech Unlimited.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like