Preface: UPNP NOTIFY overflowLogo -Internet Security Systems

UPNP NOTIFY overflow

advICE :Intrusions : 2004303
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?
Summary

An attacker can send a specially formatted version of the UPnP NOTIFY directive, causing a buffer overflow. This can potentially be exploited to gain control over a target system. Default installations of Windows XP systems are especially vulnerable.

Details

The Universal Plug and Play service, included with Windows XP and Windows ME, and optionally with Windows 98, can be exploited in this manner. A default installation of the original Windows XP release is particularly vulnerable. If you have any of these operating systems, you should visit the Microsoft Web site and upgrade your system with the necessary security fixes.

 more information
Microsoft Security Bulletin MS01-059  
 
BugtraqID: 3723   Microsoft UPnP NOTIFY Buffer Overflow Vulnerability
 
 
Version appeared: 3.1 

Privacy Policy |  Copyright Info