Vulnerabilities > CVE-2001-0877 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 4 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_XP_MS01-059.NASL |
description | Using a specially crafted NOTIFY directive, a remote attacker can cause code to run in the context of the Universal Plug and Play (UPnP) subsystem or possibly launch a denial of service attack against the affected host. Note that, under Windows XP, the UPnP subsystem operates with SYSTEM privileges. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10835 |
published | 2002-01-25 |
reporter | This script is Copyright (C) 2002-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10835 |
title | MS01-059: Unchecked Buffer in Universal Plug and Play can Lead to System Compromise (315000) |
code |
|
References
- http://marc.info/?l=bugtraq&m=100887440810532&w=2
- http://marc.info/?l=bugtraq&m=100887440810532&w=2
- http://marc.info/?l=ntbugtraq&m=100887271006313&w=2
- http://marc.info/?l=ntbugtraq&m=100887271006313&w=2
- http://www.cert.org/advisories/CA-2001-37.html
- http://www.cert.org/advisories/CA-2001-37.html
- http://www.ciac.org/ciac/bulletins/m-030.shtml
- http://www.ciac.org/ciac/bulletins/m-030.shtml
- http://www.kb.cert.org/vuls/id/411059
- http://www.kb.cert.org/vuls/id/411059
- http://www.securityfocus.com/archive/1/249238
- http://www.securityfocus.com/archive/1/249238
- http://www.securityfocus.com/bid/3724
- http://www.securityfocus.com/bid/3724
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-059
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-059
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7722
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7722