SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#951555

Microsoft Windows Universal Plug and Play (UPNP) vulnerable to buffer overflow via malformed advertisement packets

Overview

A buffer overflow in Universal Plug and Play (UPnP) service on Microsoft Windows XP, Microsoft Windows ME, and Microsoft Windows 98 permits an intruder to run arbitrary code on vulnerable systems.

I. Description

Universal Plug and Play (UPnP) is a system to allow network devices to operate together. A vulnerability in the Microsoft Windows XP and Windows ME implementation of UPnP may permit an intruder to execute arbitrary code with SYSTEM privileges. Additionally, Windows 98 and Windows 98SE may be affected if you have installed the Windows XP Internet Connection Sharing client. These vulnerabilities were discovered by Eeye Digital Security. For more information, see

II. Impact

An intruder can run arbitrary code in the local SYSTEM security context.

III. Solution

Apply a patch as described in MS01-059.

Systems Affected

VendorStatusDate NotifiedDate Updated
MicrosoftVulnerable20-Dec-2001

References


http://www.eeye.com/html/Research/Advisories/AD20011220.html
http://www.microsoft.com/technet/security/bulletin/MS01-059.asp
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=34991
http://download.microsoft.com/download/winme/Update/22940/WinMe/EN-US/314757USAM.EXE
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=34951
http://www.upnp.org/download/draft_cai_ssdp_v1_03.txt
http://www.upnp.org/download/UPnP_Vendor_Implementation_Guide_Jan2001.htm

Credit

Our thanks to Eeye Digital Security, who discovered the problem, and Microsoft for the information contained in their bulletins.

This document was written by Shawn Hernan.

Other Information

Date Public:2001-12-20
Date First Published:2001-12-20
Date Last Updated:2001-12-20
CERT Advisory: 
CVE-ID(s):CAN-2001-0876
NVD-ID(s):CAN-2001-0876
US-CERT Technical Alerts: 
Metric:51.64
Document Revision:7

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader