All the latest UK technology news, reviews and analysis

Hackers exploit Windows UPnP flaw

by Ken Young

21 Nov 2005

Comments: 2

  • Tweet this
Microsoft
Flaw affect Windows memory allocation functions

Hackers have developed proof-of-concept code that attempts to take advantage of an unpatched Windows vulnerability to crash systems, according to a security alert from Microsoft which rates the risk as 'low'.

The code disables machines running Windows XP SP1 and Windows 2000 SP4 in certain configurations by taking advantage of flaws in Windows memory allocation functions.

The vulnerability manifests itself when a malformed request is made to the UPnP service in the data section of a call to the GetDeviceList function.

In handling this request, memory consumption on vulnerable Windows boxes increases to the point where the system becomes unresponsive. Repeated requests can therefore be used to mount denial of service attacks.

However, attacks on Windows XP SP1 would require user authentication, thus reducing the scope for mischief by remote hackers.

In addition Microsoft users running Windows XP Service Pack 2, Windows Server 2003 and Windows Server 2003 Service Pack 1 are not affected by the vulnerability.
Windows 2000 shops are most at risk but effective firewalls are all that is needed to thwart attacks. Microsoft has yet to develop a security fix.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Salesforce.com Tech/Func Consultants, £50-70K + Bens, UK

Salesforce.com Consultants, both Functional or Technical...

Enterprise Data Architect - £95k

Enterprise Data Architect required by reputable Banking...

BI Developer / Data warehousing Developer - SSAS, SSRS

SSIS, SSAS, MDX, OLAP, OLTP, Data Warehousing, Data Modelling...

Senior Network Engineer

Specialist IT service provider is looking to recruit...

To send to more than one email address, simply separate each address with a comma.