← Vulnerability feed

Vulnerability record · CVE-2001-0876 · published 20 December 2001

CVE-2001-0876: Windows UPnP NOTIFY Location buffer overflow allows remote code execution

Microsoft · Windows 98

A buffer overflow exists in the Universal Plug and Play (UPnP) implementation on Windows 98, 98SE, ME, and XP. A remote attacker can trigger it by sending a NOTIFY directive containing an overly long Location URL. Because the flaw is reachable over the network without authentication, it is a serious pre-auth remote code execution issue on the affected legacy platforms.

7.5 CVSS 2.0 High EPSS 49% · top 1.1%
7.5CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityPre-authentication remote code execution with a high EPSS score, though limited to legacy Windows versions and with no confirmed KEV or ransomware use.

What it is

A buffer overflow exists in the Universal Plug and Play (UPnP) implementation on Windows 98, 98SE, ME, and XP. A remote attacker can trigger it by sending a NOTIFY directive containing an overly long Location URL. Because the flaw is reachable over the network without authentication, it is a serious pre-auth remote code execution issue on the affected legacy platforms.

Impact

An attacker can execute arbitrary code with the privileges of the UPnP service, which on these Windows versions typically runs with SYSTEM-level rights. This gives full control of the host, including data theft, malware installation, and use as a pivot point.

Attack surface

Reached over the network via UPnP/SSDP traffic; the CVSS vector AV:N/AC:L/Au:N confirms no authentication and no user interaction are required. Any host on the same network segment that can send a crafted NOTIFY message can reach the vulnerable service.

Exploitation

The record does not list this CVE in CISA KEV and shows no ransomware association, but EPSS is high at roughly 0.49 (98.8th percentile), indicating elevated predicted exploitation activity. Reference tags include Patch and Vendor Advisory, but no public exploit tag is present in the supplied data.

What to do

  • Apply the Microsoft security bulletin MS01-059 patch for the affected Windows versions.
  • Disable or block UPnP/SSDP (UDP 1900 and related ports) at network boundaries and on hosts that do not require it.
  • Segment or isolate legacy Windows 98, 98SE, ME, and XP systems that cannot be patched.
  • Restrict inbound NOTIFY/SSDP traffic to trusted internal sources only.
  • Retire or replace end-of-life Windows versions where patching is no longer possible.

Detection

  • Monitor network traffic for SSDP NOTIFY messages with abnormally long Location headers or oversized URLs.
  • Alert on UPnP/SSDP traffic originating from untrusted or external network segments.
  • Review host logs for unexpected process creation or crashes in the UPnP service (ssdpsrv) on affected systems.
  • Baseline normal UPnP discovery traffic and flag deviations in message size or frequency.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0876 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2013-3918Microsoft Windows InformationCardSigninHelper ActiveX out-of-bounds writeThe InformationCardSigninHelper ActiveX control in icardie.dll contains an out-of-bounds write that can be triggered by a crafted web page rendered i…KEVEPSS 74%analysed8.8CVE-2011-3402Microsoft Windows TrueType Font Parsing Remote Code ExecutionThe TrueType font parsing engine in win32k.sys on multiple Windows versions fails to properly handle crafted font data, allowing remote code executio…KEVEPSS 78%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2013-5065Microsoft Windows NDProxy.sys kernel local privilege escalationNDProxy.sys in the Windows kernel on Windows XP SP2/SP3 and Server 2003 SP2 fails to properly validate input, letting a local user escalate privilege…KEVEPSS 35%analysed7.8CVE-2013-3660Microsoft Windows win32k EPATHOBJ pointer flaw allows privilege escalationThe EPATHOBJ::pprFlattenRec function in win32k.sys fails to properly initialize a pointer for the next object in a list, letting a local user gain wr…KEVEPSS 39%analysed7.8CVE-2012-0151Microsoft Windows Authenticode Signature Verification PE Digest Validation FlawThe Authenticode Signature Verification function (WinVerifyTrust) in multiple Microsoft Windows versions fails to properly validate the digest of a s…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2001-0876), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.