CERT-In Vulnerability Note
CIVN-2007-0147
Information Disclosure Vulnerability in Microsoft Web Proxy Auto-Discovery WPAD
Original Issue Date:December 05, 2007
Severity Rating: MEDIUM
Systems Affected
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2
- Windows XP Professional x64 Edition and With Service Pack 2
- Windows Server 2003 Service Pack 1 and Service Pack 2
- Windows Server 2003 for Itanium-based Systems with SP 1 and SP2
- Windows Server 2003 x64 Edition and with Service Pack 2
- Windows Vista
- Windows Vista x64 Edition
- Internet Explorer 5.01 Service Pack 4
- Internet Explorer 6
- Internet Explorer 6 for Windows XP Service Pack 2
- Internet Explorer 6 for Windows Server 2003 Service Pack 1 and Service Pack 2
- Internet Explorer 6 for Windows Server 2003 for Itanium-based Systems with SP1 and SP2
- Internet Explorer 6 for Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
- Internet Explorer 7 for Windows XP Service Pack 2
- Internet Explorer 7 for Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
- Internet Explorer 7 for Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems
- Internet Explorer 7 for Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
- Internet Explorer 7 for Windows Vista
- Internet Explorer 7 for Windows Vista x64 Edition
Overview
A vulnerability has been reported in Microsoft Web Proxy Auto-Discovery. This vulnerability could be exploited by a remote attacker by hosting a WPAD server to obtain the sensitive information of the sub domains.
Description
The Web Proxy Auto-Discovery WPAD is a method used by web browsers, primarily Internet Explorer, to locate a proxy auto-config file automatically and use this to configure the browsers web proxy settings.
This vulnerability is exists in Microsoft Web Proxy Auto-Discovery WPAD while resolving hostnames that do not include a fully-qualified domain name FQDN .The attacker can host a WAPD server , establishing it as a proxy server to conduct man-in-the-middle attacks against users whose domains are registered as a sub domain to a second-level domain SLD .When visiting this WAPD server would allow remote attacker to obtain sensitive information of the sub domains.
Workaround
- Create a WPAD.DAT Proxy Auto Configuration File on a Host Named WPAD to Direct Web Browsers to Your Proxy
- Disable 'Automatically Detect Settings' in Internet Explorer
- Disable DNS Devolution
- Configure a Domain Suffix Search List
For details regarding implementation of these workarounds and related impact, refer to Microsoft Security Advisory 945713
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/advisory/945713.mspx
References
SecurityTracker
http://www.securitytracker.com/alerts/2007/Dec/1019033.html
Security Focus
http://www.securityfocus.com/bid/26686/info
CVE Name
CVE-2007-5355
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|