Vulnerability in Universal Plug and Play Could Allow Remote Code Execution (931261)
A remote code execution vulnerability exists in the Universal Plug and Play (UPnP) service in the way that it handles specially crafted HTTP requests. These HTTP requests could only be sent directly to a target computer by an attacker on the same subnet. The Windows XP firewall and the protocol enforce this subnet restriction. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the Local Service account.
Disclaimer: This webpage is intended to provide you information about patch announcements for certain specific software products. The information is provided "As Is" without warranty of any kind. The links provided point to pages on the vendors' websites. You can get more information by clicking the links to visit the relevant pages on the vendors' websites. Desktop Central is NOT endorsed by the vendors of the software products.