Port 5357: Web Services on Devices API
Port 5357 is used by the Microsoft Web Services on Devices API (WSDAPI), which implements the Devices Profile for Web Services for Windows device discovery and control. Discovery itself uses WS-Discovery on UDP 3702, while Microsoft lists TCP 5357 and 5358 as the inbound ports that receive WSD messages. IANA registers wsdapi on TCP and UDP 5357.
Port Details
Security Exposure
WSDAPI parses messages from other hosts, so a flaw in that parser can be reached by anyone allowed through the firewall. Microsoft bulletin MS09-063 fixed a critical memory corruption issue in WSDAPI (CVE-2009-2512) and noted that the Windows Firewall only exposes the service to the local subnet. Exposing 5357 beyond the local network adds attack surface without a business need.
Hardening
- +Block inbound TCP 5357 and 5358 at the network perimeter.
- +Keep the Windows Firewall rule for WSD scoped to the local subnet, which is the default Microsoft describes.
- +Block WSD where device discovery is not needed; Microsoft notes that blocking the WSD ports stops device discovery.
- +Apply Windows security updates promptly.
Monitoring
Alert on inbound connections to TCP 5357 from outside the local subnet and on unexpected hosts listening on 5357 or 5358.
Tools for Auditing and Monitoring WSDAPI
Microsoft Defender for Endpoint
CommercialMicrosoft enterprise EDR covering Windows, macOS, Linux, and mobile from one console.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Related Tool Categories
Frequently Asked Questions
What is port 5357 on Windows?→
It is the WSDAPI port used by Web Services on Devices for network discovery of printers and other devices. Microsoft documents TCP 5357 and 5358 together with UDP 3702 for WS-Discovery.
Can port 5357 be blocked?→
Microsoft listed blocking inbound TCP 5357 and 5358 and outbound UDP 3702 as a workaround in MS09-063. Blocking it disables WSD-based device discovery.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5357 is not guaranteed to be WSDAPI. Exploited-in-the-wild data from the CISA KEV catalog (CC0).