Microsoft Universal Plug and Play Simple Service Discovery Protocol Denial of Service Vulnerability
BID:3724
Info
Microsoft Universal Plug and Play Simple Service Discovery Protocol Denial of Service Vulnerability
| Bugtraq ID: | 3724 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2001 12:00AM |
| Updated: | Dec 20 2001 12:00AM |
| Credit: | Discovery by Riley Hassell <[email protected]> of eEye Digital Security. |
| Vulnerable: |
Microsoft Windows XP Professional Microsoft Windows XP Home Microsoft Windows ME Microsoft Windows 98SE Microsoft Windows 98 |
| Not Vulnerable: | |
Discussion
Microsoft Universal Plug and Play Simple Service Discovery Protocol Denial of Service Vulnerability
Universal Plug and Play, or UPnP, is a service that allows for hosts to locate and use devices on the local network. UPnP support ships with Windows XP and ME. For Windows 98 and 98SE, it is available with Windows XP's Internet Connection Sharing client.
The Simple Service Discovery Protocol (SSDP) is a component of UPnP that allows a system to enumerate the resources of a newly installed network device on a UPnP network. This service is vulnerable to a denial of service condition by constructing a UDP packet directed at a UPnP-enabled system which directs the system to an echoed port, the system would enter into an endless download cycle.
This vulnerability could possibly be used to launch a distributed denial of service attack by directing several UPnP-enabled systems at a third party.
Universal Plug and Play, or UPnP, is a service that allows for hosts to locate and use devices on the local network. UPnP support ships with Windows XP and ME. For Windows 98 and 98SE, it is available with Windows XP's Internet Connection Sharing client.
The Simple Service Discovery Protocol (SSDP) is a component of UPnP that allows a system to enumerate the resources of a newly installed network device on a UPnP network. This service is vulnerable to a denial of service condition by constructing a UDP packet directed at a UPnP-enabled system which directs the system to an echoed port, the system would enter into an endless download cycle.
This vulnerability could possibly be used to launch a distributed denial of service attack by directing several UPnP-enabled systems at a third party.
Exploit / POC
Microsoft Universal Plug and Play Simple Service Discovery Protocol Denial of Service Vulnerability
In order to exploit this vulnerability, the attacker simply has to construct a UDP NOTIFY packet which specifies a certain IP address and port number.
In order to exploit this vulnerability, the attacker simply has to construct a UDP NOTIFY packet which specifies a certain IP address and port number.
Solution / Fix
Microsoft Universal Plug and Play Simple Service Discovery Protocol Denial of Service Vulnerability
Solution:
Microsoft has released a patch to address this issue:
Microsoft Windows 98
Microsoft Windows 98SE
Microsoft Windows ME
Microsoft Windows XP Home
Microsoft Windows XP Professional
Solution:
Microsoft has released a patch to address this issue:
Microsoft Windows 98
-
Microsoft Q314941
Patch for MS01-059.
http://download.microsoft.com/download/win98SE/Patch/Q314941/W98/EN-US /314941USA8.EXE
Microsoft Windows 98SE
-
Microsoft Q314941
Patch for MS01-059.
http://download.microsoft.com/download/win98SE/Patch/Q314941/W98/EN-US /314941USA8.EXE
Microsoft Windows ME
-
Microsoft Q314757
Patch for MS01-059.
http://download.microsoft.com/download/winme/Update/22940/WinMe/EN-US/ 314757USAM.EXE
Microsoft Windows XP Home
-
Microsoft Q315000
Patch for MS01-059
http://download.microsoft.com/download/whistler/Patch/Q315000/WXP/EN-U S/Q315000_WXP_SP1_x86_ENU.exe
Microsoft Windows XP Professional
-
Microsoft Q315000
Patch for MS01-059
http://download.microsoft.com/download/whistler/Patch/Q315000/WXP/EN-U S/Q315000_WXP_SP1_x86_ENU.exe
References
Microsoft Universal Plug and Play Simple Service Discovery Protocol Denial of Service Vulnerability
References:
References:
- Microsoft Security Bulletin MS01-059 (Microsoft)
- Technet Security (Microsoft)