Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.10835
Category:Windows : Microsoft Bulletins
Title:Unchecked Buffer in XP upnp
Summary:Unchecked Buffer in Universal Plug and Play Can; Lead to System Compromise for Windows XP (Q315000)
Description:Summary:
Unchecked Buffer in Universal Plug and Play Can
Lead to System Compromise for Windows XP (Q315000)

Vulnerability Impact:
By sending a specially-malformed NOTIFY directive,
it would be possible for an attacker to cause code to run in the context of the UPnP
service, which runs with system privileges on Windows XP.

The UPnP implementations do not adequately regulate how it performs this operation,
and this gives rise to two different denial-of-service scenarios. (CVE-2001-0877)

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: BugTraq ID: 3723
Common Vulnerability Exposure (CVE) ID: CVE-2001-0876
http://www.securityfocus.com/bid/3723
Bugtraq: 20011220 Multiple Remote Windows XP/ME/98 Vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=100887440810532&w=2
http://www.cert.org/advisories/CA-2001-37.html
CERT/CC vulnerability note: VU#951555
http://www.kb.cert.org/vuls/id/951555
Computer Incident Advisory Center Bulletin: M-030
http://www.ciac.org/ciac/bulletins/m-030.shtml
Microsoft Security Bulletin: MS01-059
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-059
http://marc.info/?l=ntbugtraq&m=100887271006313&w=2
XForce ISS Database: win-upnp-notify-bo(7721)
https://exchange.xforce.ibmcloud.com/vulnerabilities/7721
CopyrightThis script is Copyright (C) 2002 Michael Scheidell

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.