First published: Thu Dec 20 2001(Updated: )
Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 98SE | ||
Microsoft Windows Me | ||
Microsoft Windows 98 | =gold | |
Microsoft Windows XP | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0877 is classified as a high severity vulnerability due to its potential to cause denial of service.
To mitigate CVE-2001-0877, it is recommended to disable Universal Plug and Play (UPnP) on affected Windows operating systems.
CVE-2001-0877 affects Windows 98, Windows 98SE, Windows Me, and Windows XP.
CVE-2001-0877 can lead to a denial of service by allowing attackers to generate excessive traffic through spoofed SSDP advertisements.
Individuals and systems running the specified versions of Windows are potential targets for exploitation of CVE-2001-0877.