With great power comes great potential for mischief. Well at least if its
Microsoft’s. There has been endless debate on Windows XP’s Universal Plug and
Play. Whether the feature is a security bomb; whether it just has bugs; whether
you should disable it; … I would disable the UPnP service but the following
are you to make a more informed decision:
- Unchecked Buffer in Universal Plug and Play Service
- Q315000 : Unchecked Buffer in Universal Plug and Play Can Lead to
System Compromise for Windows XP
- Q309073 : Invalid Universal Plug and Play Request can Disrupt
System Operation
- CERT®
Advisory CA-2001-37 Buffer Overflow in UPnP Service On Microsoft Windows
- UnPlug n’ Pray
utility disables UPnP (freeware)
- Multiple Vulnerabilities in Microsoft Universal Plug and Play
- Universal Plug and Play Technology