All the latest UK technology news, reviews and analysis

DoS vulnerability found in Windows XP

by Andy McCue

14 Nov 2001

Be the first to comment

  • Tweet this

A flaw in the Universal Plug and Play (UPnP) facility in Microsoft's Windows XP could enable a hacker to launch a denial of service attack.

UPnP is a Microsoft-backed industry standard which uses web protocols and allows PCs, printers and wireless devices plugged into a network to automatically communicate with each other.

On Windows XP systems each UPnP request uses memory that is not being freed up because of a memory leak error.

A hacker could manipulate the error by exhausting the system's memory resources via repeatedly sending invalid UPnP data to the target system. The flaw also affects Windows 98 and ME systems.

Microsoft has been forced to issue a warning and a patch is now available, although the risk is classified as low.

Standard firewall practices, such as blocking ports 1900 and 5000, and activating the Windows XP default firewall would impede an attacker's ability to locate and attack the system.

The Microsoft advisory on this bug can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

C#, WPF, Silverlight, UI Development, Software Engineers

C#, WPF, Silverlight, UI Development, Software Engineers...

Operations Manager

Candidate required who is used to working in a client...

Build Change Release Manager / Build Change Manager / Liverpool

Build Change Release Manager / Build Change Manager...

IT Service Desk Manager / Liverpool / Up to £60,000

IT Service Desk Manager / Liverpool / Up to £60,000...

To send to more than one email address, simply separate each address with a comma.