PT-2007-2629 · Microsoft · Windows Xp+1
Publicado
2007-04-10
·
Atualizado
2018-10-16
·
CVE-2007-1204
CVSS v2.0
6.8
Média
| Vetor | AV:A/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP SP2
Description
A stack-based buffer overflow issue exists in the Universal Plug and Play (UPnP) service, allowing remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages. This triggers memory corruption. The vulnerability enables an attacker to run arbitrary code in the context of the local service by sending specially crafted HTTP requests.
Recommendations
For Microsoft Windows XP SP2, consider disabling the UPnP service as a temporary workaround until a patch is available. Restrict access to the UPnP service to minimize the risk of exploitation. Avoid using the vulnerable UPnP service in the affected HTTP requests until the issue is resolved.
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows Xp
Windows