Click Here to Install Silverlight*
United StatesChange|All Microsoft Sites
Microsoft
Download Center 
Search Advanced Search

Windows XP Security Patch: Unchecked Buffer in UPnP Can Lead to System Compromise

Brief Description
This update resolves the “Unchecked Buffer in Universal Plug and Play Can Lead to System Compromise” security vulnerability in Windows XP. Download now to prevent a malicious user from compromising your computer, or using it to interfere with another computer's operation.

On This Page

Quick Details
File Name:Q315000_WXP_SP1_x86_ENU.exe
Version:Q315000
Security Bulletins:MS01-054
Knowledge Base (KB) Articles:KB315000
Date Published:12/19/2001
Language:English
Download Size:586 KB
Estimated Download Time: 2 min 56K

Change Language:
  

Overview

This update resolves the “Unchecked Buffer in Universal Plug and Play Can Lead to System Compromise” security vulnerability in Windows XP. Download now to prevent a malicious user from compromising your computer, or using it to interfere with another computer's operation. The vulnerability results because the Windows XP Universal Plug and Play feature does not correctly validate inputs before using them. The patch also eliminates the vulnerability discussed in Microsoft Security Bulletin MS01-059.

 Top of page

System Requirements

  • Supported Operating Systems: Windows XP
  • Windows XP Professional
  • Windows XP Home Edition

 Top of page

Instructions

  1. Click the Download button on this page to start the download, or choose a different language from the drop-down list and click Go.
  2. Do one of the following:
    • To start the installation immediately, click Open or Run this program from its current location.
    • To copy the download to your computer for installation at a later time, click Save or Save this program to disk.

 Top of page

Additional Information

Who should read this bulletin: Customers using Microsoft Windows XP Professional or Home Edition, or who have installed the Windows XP Internet Connection Sharing client on Windows 98 or 98SE.

Impact of vulnerability: Run code of attacker’s choice.

Maximum Severity Rating: Critical

Recommendation: Microsoft strongly urges all Windows XP customers to apply the patch immediately. Customers using Windows 98, 98SE or ME should apply the patch if Universal Plug and Play support is installed and running.

Affected Software:
  • Microsoft Windows 98
  • Microsoft Windows 98SE
  • Microsoft Windows Me
  • Microsoft Windows XP

 Top of page

 Top of page

 Top of page


© 2009 Microsoft Corporation. All rights reserved. Contact Us |Terms of Use |Trademarks |Privacy Statement