CVE-2007-1692: High severity Microsoft Windows 2000 vulnerability
The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer. NOTE: it could be argued that if an attacker already has control over WINS/DNS, then web traffic could already be intercepted by modifying WINS or DNS records, so this would not cross privilege boundaries and would not be a vulnerability. It has also been reported that DHCP is an alternate attack vector.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1692?
CVE-2007-1692 has been assessed as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2007-1692?
To mitigate CVE-2007-1692, disable WPAD or configure static WPAD entries in your network settings.
Who is affected by CVE-2007-1692?
CVE-2007-1692 affects users of Microsoft Windows 2000 and Windows 2003 Server without proper configuration.
Can CVE-2007-1692 lead to data interception?
Yes, CVE-2007-1692 can allow remote attackers to intercept web traffic if a rogue proxy server is registered.
What is the Web Proxy Autodiscovery Protocol related to CVE-2007-1692?
The Web Proxy Autodiscovery Protocol enables automatic detection of proxy settings, which can be exploited in CVE-2007-1692.