PT-2001-2041 · Microsoft · Windows 98Se+4
Published
2001-12-20
·
Updated
2018-10-12
·
CVE-2001-0877
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Windows versions 98, 98SE, ME, and XP
Description
The issue allows remote attackers to cause a denial of service. This can be achieved through a spoofed SSDP advertisement that causes the client to connect to a service on another machine generating a large amount of traffic, or via a spoofed SSDP announcement to broadcast or multicast addresses, potentially causing all clients to send traffic to a single target system.
Recommendations
For Windows 98, 98SE, ME, and XP, consider disabling the Universal Plug and Play (UPnP) service to prevent exploitation until a fix is available. Restrict access to SSDP announcements and advertisements to minimize the risk of denial of service attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Universal Plug/Play
Windows 98
Windows 98Se
Windows Me
Windows Xp