CVE-2007-1692

Microsoft Windows 2000 and 2003 Server - Network Traffic Hijacking via WPAD Proxy Autodiscovery

Title source: llm
STIX 2.1

Description

The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer. NOTE: it could be argued that if an attacker already has control over WINS/DNS, then web traffic could already be intercepted by modifying WINS or DNS records, so this would not cross privilege boundaries and would not be a vulnerability. It has also been reported that DHCP is an alternate attack vector.

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/kb/934864
Various Sources x_refsource_misc
http://isc.sans.org/diary.html?storyid=2517
Third Party Advisory mailing-list x_refsource_mlist
http://archives.neohapsis.com/archives/isn/2007-q1/0418.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1115
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33244

Scores

EPSS 0.1525
EPSS Percentile 96.4%

Details

CWE
CWE-16
Status published
Products (3)
microsoft/windows_2000
microsoft/windows_2003_server 2000
microsoft/windows_2003_server r2
Published Mar 26, 2007
Tracked Since Feb 18, 2026