CVE-2001-0877: Medium severity Microsoft Windows 98SE vulnerability
Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0877?
CVE-2001-0877 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2001-0877?
To mitigate CVE-2001-0877, it is recommended to disable Universal Plug and Play (UPnP) on affected Windows operating systems.
Which versions of Windows are affected by CVE-2001-0877?
CVE-2001-0877 affects Windows 98, Windows 98SE, Windows Me, and Windows XP.
What is the impact of CVE-2001-0877?
CVE-2001-0877 can lead to a denial of service by allowing attackers to generate excessive traffic through spoofed SSDP advertisements.
Who can be targeted by CVE-2001-0877?
Individuals and systems running the specified versions of Windows are potential targets for exploitation of CVE-2001-0877.