Vulnerability record · CVE-2001-0876 · published 20 December 2001
CVE-2001-0876: Windows UPnP NOTIFY Location buffer overflow allows remote code execution
Microsoft · Windows 98
A buffer overflow exists in the Universal Plug and Play (UPnP) implementation on Windows 98, 98SE, ME, and XP. A remote attacker can trigger it by sending a NOTIFY directive containing an overly long Location URL. Because the flaw is reachable over the network without authentication, it is a serious pre-auth remote code execution issue on the affected legacy platforms.
Description
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPre-authentication remote code execution with a high EPSS score, though limited to legacy Windows versions and with no confirmed KEV or ransomware use.
What it is
A buffer overflow exists in the Universal Plug and Play (UPnP) implementation on Windows 98, 98SE, ME, and XP. A remote attacker can trigger it by sending a NOTIFY directive containing an overly long Location URL. Because the flaw is reachable over the network without authentication, it is a serious pre-auth remote code execution issue on the affected legacy platforms.
Impact
An attacker can execute arbitrary code with the privileges of the UPnP service, which on these Windows versions typically runs with SYSTEM-level rights. This gives full control of the host, including data theft, malware installation, and use as a pivot point.
Attack surface
Reached over the network via UPnP/SSDP traffic; the CVSS vector AV:N/AC:L/Au:N confirms no authentication and no user interaction are required. Any host on the same network segment that can send a crafted NOTIFY message can reach the vulnerable service.
Exploitation
The record does not list this CVE in CISA KEV and shows no ransomware association, but EPSS is high at roughly 0.49 (98.8th percentile), indicating elevated predicted exploitation activity. Reference tags include Patch and Vendor Advisory, but no public exploit tag is present in the supplied data.
What to do
- Apply the Microsoft security bulletin MS01-059 patch for the affected Windows versions.
- Disable or block UPnP/SSDP (UDP 1900 and related ports) at network boundaries and on hosts that do not require it.
- Segment or isolate legacy Windows 98, 98SE, ME, and XP systems that cannot be patched.
- Restrict inbound NOTIFY/SSDP traffic to trusted internal sources only.
- Retire or replace end-of-life Windows versions where patching is no longer possible.
Detection
- Monitor network traffic for SSDP NOTIFY messages with abnormally long Location headers or oversized URLs.
- Alert on UPnP/SSDP traffic originating from untrusted or external network segments.
- Review host logs for unexpected process creation or crashes in the UPnP service (ssdpsrv) on affected systems.
- Baseline normal UPnP discovery traffic and flag deviations in message size or frequency.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0876 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0876), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.