Skip to main content

Port Details

Port
5357
Transport
TCP
Service
WSDAPI
IANA service name
wsdapi
Range
User port (1024-49151)
Related ports
37025358

Security Exposure

WSDAPI parses messages from other hosts, so a flaw in that parser can be reached by anyone allowed through the firewall. Microsoft bulletin MS09-063 fixed a critical memory corruption issue in WSDAPI (CVE-2009-2512) and noted that the Windows Firewall only exposes the service to the local subnet. Exposing 5357 beyond the local network adds attack surface without a business need.

Hardening

  • +Block inbound TCP 5357 and 5358 at the network perimeter.
  • +Keep the Windows Firewall rule for WSD scoped to the local subnet, which is the default Microsoft describes.
  • +Block WSD where device discovery is not needed; Microsoft notes that blocking the WSD ports stops device discovery.
  • +Apply Windows security updates promptly.

Monitoring

Alert on inbound connections to TCP 5357 from outside the local subnet and on unexpected hosts listening on 5357 or 5358.

Tools for Auditing and Monitoring WSDAPI

SIEM Tools

Microsoft enterprise EDR covering Windows, macOS, Linux, and mobile from one console.

LicenseProprietary
PlatformWindows, macOS, Linux, iOS, Android, Web

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Frequently Asked Questions

What is port 5357 on Windows?→

It is the WSDAPI port used by Web Services on Devices for network discovery of printers and other devices. Microsoft documents TCP 5357 and 5358 together with UDP 3702 for WS-Discovery.

Can port 5357 be blocked?→

Microsoft listed blocking inbound TCP 5357 and 5358 and outbound UDP 3702 as a workaround in MS09-063. Blocking it disables WSD-based device discovery.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5357 is not guaranteed to be WSDAPI. Exploited-in-the-wild data from the CISA KEV catalog (CC0).