PT-2007-2629 · Microsoft · Windows Xp+1
Published
2007-04-10
·
Updated
2018-10-16
·
CVE-2007-1204
CVSS v2.0
6.8
Medium
| Vector | AV:A/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP SP2
Description
A stack-based buffer overflow issue exists in the Universal Plug and Play (UPnP) service, allowing remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages. This triggers memory corruption. The vulnerability enables an attacker to run arbitrary code in the context of the local service by sending specially crafted HTTP requests.
Recommendations
For Microsoft Windows XP SP2, consider disabling the UPnP service as a temporary workaround until a patch is available. Restrict access to the UPnP service to minimize the risk of exploitation. Avoid using the vulnerable UPnP service in the affected HTTP requests until the issue is resolved.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Xp
Windows