BleepingComputer.com: Unpatched Windows Ssdp/upnp Local Vulnerability & Poc Exploit

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Unpatched Windows Ssdp/upnp Local Vulnerability & Poc Exploit

#1 User is offline   harrywaldron 

  • Security Reporter
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 509
  • Joined: 10-April 04
  • Gender:Male
  • Location:Roanoke, Virginia

  Posted 02 February 2006 - 08:11 PM

Quote

Advisory ID : FrSIRT/ADV-2006-0417
CVE ID : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable : No
Locally Exploitable : Yes
Release Date : 2006-02-02

EXPLOIT: POC exploit code can be found at FrSIRT

Technical Description: A vulnerability has been identified in Microsoft Windows, which could be exploited by malicious users to obtain elevated privileges. This flaw is due to an access validation in the Simple Service Discovery Protocol (SSDP) Discovery and the Universal Plug and Play Device Host (UPnP) services that fail to properly validate user permissions, which could be exploited by local unprivileged attackers to bypass security restrictions and execute malicious programs with elevated privileges.



Thankfully, this new vulnerability is not remotely exploitable as it requires local access to the PC. Still, someone with a crafted version of the exploit on a memory stick or other media might be able to compromise security controls on the local PC.


Microsoft Windows SSDP and UPnP Services Privilege Escalation Issue
http://www.frsirt.com/english/advisories/2006/0417

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users