PT-2007-6415 · Microsoft · Internet Explorer

Published

2007-12-05

·

Updated

2021-07-23

·

CVE-2007-5355

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer versions 6 through 7
Description: The issue concerns the Web Proxy Auto-Discovery (WPAD) feature. When a primary DNS suffix with three or more components is configured, it resolves an unqualified wpad hostname in a second-level domain outside this configured DNS domain. This allows remote WPAD servers to conduct man-in-the-middle (MITM) attacks.
Recommendations: For Microsoft Internet Explorer versions 6 through 7, consider disabling the WPAD feature as a temporary workaround until a patch is available. Restrict access to external WPAD servers to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-5355

Affected Products

Internet Explorer