New vulnerability in Windows network features
Microsoft has detailed a dangerous vulnerability in Windows' network support functionality that could be exploited by attackers, navigating Internet bandwidth through a 'malicious' proxy server.
Microsoft said that currently only versions of Windows 2003 and Windows 2000 (see details below) are affected by this error, and Microsoft has also provided details on how to configure DNS and WINS to maintain posting. Sign WPAD (Web Proxy Automatic Discovery).
The attacker can control to register to enter a WPAD entry in DNS or in WINS, processing to a server via a reconstructed Wpad.dat file and then, WPAD stations can be navigated. Their Internet bandwidth is via a malicious proxy server.
Microsoft recommends that network administrators admin update how to configure DNS and WINS here (KB934864).
Windows operating system versions are affected by errors:
-
Microsoft Windows Server 2003 R2 Standard Edition (32-bit x86)
-
Microsoft Windows Server 2003 R2 Enterprise Edition (32-Bit x86)
-
Microsoft Windows Server 2003 R2 Datacenter Edition (32-Bit x86)
-
Microsoft Windows Server 2003 R2 Standard x64 Edition
-
Microsoft Windows Server 2003 R2 Enterprise x64 Edition
-
Microsoft Windows Server 2003 R2 Datacenter x64 Edition
-
Microsoft Windows Server 2003, Standard x64 Edition
-
Microsoft Windows Server 2003, Enterprise x64 Edition
-
Microsoft Windows Server 2003, Datacenter x64 Edition
-
Microsoft Windows Server 2003 Service Pack 1, when used with:
Microsoft Windows Server 2003, Standard Edition (32-bit x86)
Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
Microsoft Windows Server 2003, Web Edition
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems -
Microsoft Windows Server 2003, Standard Edition (32-bit x86)
-
Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
-
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
-
Microsoft Windows Server 2003, Web Edition
-
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
-
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
-
Microsoft Windows Small Business Server 2003 Standard Edition
-
Microsoft Windows 2000 Service Pack 4, when used with:
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Server -
Microsoft Windows 2000 Professional Edition, when used with:
Microsoft Windows 2000 Professional Edition -
Microsoft Small Business Server 2000 Standard Edition
Tuyet Phan
- DoS application vulnerabilities in Windows XP
- Hackers exploit new Windows vulnerabilities
- Microsoft investigated the vulnerability in Windows Vista
- Windows XP SP3 will have some Vista features
- New serious vulnerability threatens IE
- 8 security features of Windows operating system
- A new vulnerability has appeared in Vista
- Windows has never seen a dangerous zero-day vulnerability
- Windows Live will be like Facebook social network
- The attack code is targeting the new IE vulnerability
- Windows Vista: Turn off unnecessary features
- Windows Mobile 6: 'Vista' for mobile phones