Microsoft
Flaw affect Windows memory allocation functions
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Hackers exploit Windows UPnP flaw

Proof-of-concept code takes advantage of unpatched vulnerability

Ken Young, vnunet.com 21 Nov 2005
ADVERTISEMENT

Hackers have developed proof-of-concept code that attempts to take advantage of an unpatched Windows vulnerability to crash systems, according to a security alert from Microsoft which rates the risk as 'low'.

The code disables machines running Windows XP SP1 and Windows 2000 SP4 in certain configurations by taking advantage of flaws in Windows memory allocation functions.

The vulnerability manifests itself when a malformed request is made to the UPnP service in the data section of a call to the GetDeviceList function.

In handling this request, memory consumption on vulnerable Windows boxes increases to the point where the system becomes unresponsive. Repeated requests can therefore be used to mount denial of service attacks.

However, attacks on Windows XP SP1 would require user authentication, thus reducing the scope for mischief by remote hackers.

In addition Microsoft users running Windows XP Service Pack 2, Windows Server 2003 and Windows Server 2003 Service Pack 1 are not affected by the vulnerability.
Windows 2000 shops are most at risk but effective firewalls are all that is needed to thwart attacks. Microsoft has yet to develop a security fix.


All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | VOSA
Management Information Analyst - Up to £30,231 plus benefits - South West This is an excellent opportunity for an experienced Business Analyst or an ambitious Information Analyst to influence a national organisation and contribute to ... more >
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
Head of Technology -Excellent Salary + Car + Benefits - Buckinghamshire Grass Roots is leading player at providing employee reward and benefits solutions to major blue chip companies.   This part of the business has grown ... more >
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Analyst Programmer - HP Service Center - Competitive Salary - Reading Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & ... more >
Central London, United Kingdom | MI5 Security Service
Enterprise Modeller - Up to £50,000 + benefits - Central London MI5 is making significant investments to enhance its technology capability and is looking for talented IT professionals to join its technology teams in central ... more >
More job opportunities