Universal Plug and Play Vulnerabilities Discovered



Universal Plug and Play Vulnerabilities Discovered
Microsoft warned users Thursday to a critical vulnerability, the universal plug-and-play services, it may lead to system compromise, several software companies in the client operating system.

Windows XP and in Windows Me are vulnerable because of their native support for Universal Plug and Play (UPnP) service, which will allow computers to discover and use Web-based equipment. Windows Me, but these services are turned off by default. Windows 98 and Windows more affected, because such services in these operating systems can be installed from the Internet Connection Sharing client, ships with Windows XP.

Windows NT Workstation and Windows 2000 Professional Edition are not affected, according to the notice, because they do not support the UPnP.

Two unrelated flaw affects UPnP against by the new patch.

First is the buffer overflow handling components in the provision of e-mail advertisements UPnP-enabled devices on the network.

Second weakness from the Universal Plug and Play the failure to limit measures, the service will be taken to obtain information from a newly discovered device, making the system vulnerable to denial-of-service of the two.

Microsoft pointed out that the standard firewall, such as blocking port from 1900 to 5000, will protect corporate networks from Internet-based attacks. The company also said that the Internet Connection Firewall by default in Windows XP operating makes it harder to attack the use of the method.

This is the 59th security bulletin, Microsoft issued in 2001. Microsoft credited eEye Digital Security on this issue.


Latest Industry News:
- Microsoft
- Free Tool Hunts Bots
- Found
- RPI, Law School Team to Offer Degrees in Tech Business Law
- Adobe's 2Q Profit Surges 24 Percent
- Duke: iPhone Not To Blame
- Cisco Closes the Books on Still Another Acquisition
- Microsoft Deal Values Facebook at $15B
- Netcraft
- Intel Unveils Low-Power Chip for 2-Way Blades
- Cisco Introduces New CallManager Security Features
- Special Report: Meta happens!
- You Move Me
- OS X Upgrade, IPhone May Boost Mac Sales
- CoSort 9 Eases Large XML/LDIF Conversion, Manipulation, Protection
- Appearance of Exploit Code Means Time Is Running Out to Apply Critical Windows Patch
- Vista Still Getting Mixed Reviews
- ISM’s PerfMan Grants IT Control over E-commerce Systems
- Making Amends
- Just What You Needed


question

MCSD .NET
70-229 70-300 70-306 70-310 70-315 70-316 70-320
$269 Details
MCAD .NET
70-305 70-306 70-310 70-315 70-316 70-320
$229 Details
LPI 2
117-201 117-202
$79 Details
CCVP
642-642 642-432 642-426 642-444 642-453
$199 Details
MCDBA
70-228 70-229 70-290 70-293
$159 Details
MCPD
70-526 70-528 70-536 70-547 70-548 70-549 70-551
$269 Details
MCTS
70-235 70-526 70-528 70-529 70-536 70-551 70-552 70-553
$309 Details
MCP
70-270 70-290
$79 Details

Hot Certifications
Top Exams