Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote malicious users to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
microsoft windows 98 |
||
microsoft windows 98se |
||
microsoft windows me |
||
microsoft windows xp |