PT-2007-6415 · Microsoft · Internet Explorer
Published
2007-12-05
·
Updated
2021-07-23
·
CVE-2007-5355
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Internet Explorer versions 6 through 7
Description:
The issue concerns the Web Proxy Auto-Discovery (WPAD) feature. When a primary DNS suffix with three or more components is configured, it resolves an unqualified wpad hostname in a second-level domain outside this configured DNS domain. This allows remote WPAD servers to conduct man-in-the-middle (MITM) attacks.
Recommendations:
For Microsoft Internet Explorer versions 6 through 7, consider disabling the WPAD feature as a temporary workaround until a patch is available. Restrict access to external WPAD servers to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer