Microsoft UPnP NOTIFY Buffer Overflow Vulnerability
BID:3723
Info
Microsoft UPnP NOTIFY Buffer Overflow Vulnerability
| Bugtraq ID: | 3723 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2001 12:00AM |
| Updated: | Dec 20 2001 12:00AM |
| Credit: | Discovery by Riley Hassell <[email protected]> of eEye Digital Security. |
| Vulnerable: |
Microsoft Windows XP Professional Microsoft Windows XP Home Microsoft Windows ME Microsoft Windows 98SE Microsoft Windows 98 |
| Not Vulnerable: | |
Discussion
Microsoft UPnP NOTIFY Buffer Overflow Vulnerability
Universal Plug and Play, or UPnP, is a service that allows for hosts to locate and use devices on the local network. UPnP support ships with Windows XP and ME. For Windows 98 and 98SE, it is available with Windows XP's Internet Connection Sharing client. It should be noted that UPnP services are enabled on Windows XP by default.
When processing the location field in a NOTIFY directive, UPnP server process memory can be overwritten by data that originated in the packet. If the IP address, port and filename components are of excessive length, access violations will occur when the server attempts to dereference pointers overwritten with data from the packet.
It should be noted that the service listens on broadcast and multicast interfaces. This could permit an attacker to exploit a number of systems without knowing their individual IP addresses, if they employed an exploitation method targeting a UDP port. It is however possible to exploit this condition using either the TCP or UDP protocols.
The UPnP service runs in the LOCAL SERVICE security context. An attacker who successfully exploits this vulnerability could gain control over the target host.
Universal Plug and Play, or UPnP, is a service that allows for hosts to locate and use devices on the local network. UPnP support ships with Windows XP and ME. For Windows 98 and 98SE, it is available with Windows XP's Internet Connection Sharing client. It should be noted that UPnP services are enabled on Windows XP by default.
When processing the location field in a NOTIFY directive, UPnP server process memory can be overwritten by data that originated in the packet. If the IP address, port and filename components are of excessive length, access violations will occur when the server attempts to dereference pointers overwritten with data from the packet.
It should be noted that the service listens on broadcast and multicast interfaces. This could permit an attacker to exploit a number of systems without knowing their individual IP addresses, if they employed an exploitation method targeting a UDP port. It is however possible to exploit this condition using either the TCP or UDP protocols.
The UPnP service runs in the LOCAL SERVICE security context. An attacker who successfully exploits this vulnerability could gain control over the target host.
Exploit / POC
Microsoft UPnP NOTIFY Buffer Overflow Vulnerability
Exploit code has been developed by Gabriel Maggiotti and is available below:
Exploit code has been developed by Gabriel Maggiotti and is available below:
Solution / Fix
Microsoft UPnP NOTIFY Buffer Overflow Vulnerability
Solution:
Fixes are available:
Microsoft Windows 98
Microsoft Windows 98SE
Microsoft Windows ME
Microsoft Windows XP Home
Microsoft Windows XP Professional
Solution:
Fixes are available:
Microsoft Windows 98
-
Microsoft Q314941
Patch for MS01-059.
http://download.microsoft.com/download/win98SE/Patch/Q314941/W98/EN-US /314941USA8.EXE
Microsoft Windows 98SE
-
Microsoft Q314941
Patch for MS01-059.
http://download.microsoft.com/download/win98SE/Patch/Q314941/W98/EN-US /314941USA8.EXE
Microsoft Windows ME
-
Microsoft Q314757
Patch for MS01-059.
http://download.microsoft.com/download/winme/Update/22940/WinMe/EN-US/ 314757USAM.EXE
Microsoft Windows XP Home
-
Microsoft Q315000
Patch for MS01-059
http://download.microsoft.com/download/whistler/Patch/Q315000/WXP/EN-U S/Q315000_WXP_SP1_x86_ENU.exe
Microsoft Windows XP Professional
-
Microsoft Q315000
Patch for MS01-059
http://download.microsoft.com/download/whistler/Patch/Q315000/WXP/EN-U S/Q315000_WXP_SP1_x86_ENU.exe
References
Microsoft UPnP NOTIFY Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS01-059 (Microsoft)
- Microsoft Technet Security (Microsoft)