PT-2007-2629 · Microsoft · Windows Xp+1

Published

2007-04-10

·

Updated

2018-10-16

·

CVE-2007-1204

CVSS v2.0

6.8

Medium

VectorAV:A/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP SP2
Description A stack-based buffer overflow issue exists in the Universal Plug and Play (UPnP) service, allowing remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages. This triggers memory corruption. The vulnerability enables an attacker to run arbitrary code in the context of the local service by sending specially crafted HTTP requests.
Recommendations For Microsoft Windows XP SP2, consider disabling the UPnP service as a temporary workaround until a patch is available. Restrict access to the UPnP service to minimize the risk of exploitation. Avoid using the vulnerable UPnP service in the affected HTTP requests until the issue is resolved.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-1204

Affected Products

Windows Xp
Windows