New vulnerability in Windows network features

Microsoft has detailed a dangerous vulnerability in Windows' network support functionality that could be exploited by attackers, navigating Internet bandwidth through a 'malicious' proxy server.

Picture 1 of New vulnerability in Windows network features Microsoft said that currently only versions of Windows 2003 and Windows 2000 (see details below) are affected by this error, and Microsoft has also provided details on how to configure DNS and WINS to maintain posting. Sign WPAD (Web Proxy Automatic Discovery).

The attacker can control to register to enter a WPAD entry in DNS or in WINS, processing to a server via a reconstructed Wpad.dat file and then, WPAD stations can be navigated. Their Internet bandwidth is via a malicious proxy server.

Microsoft recommends that network administrators admin update how to configure DNS and WINS here (KB934864).

Windows operating system versions are affected by errors:

  1. Microsoft Windows Server 2003 R2 Standard Edition (32-bit x86)
  2. Microsoft Windows Server 2003 R2 Enterprise Edition (32-Bit x86)
  3. Microsoft Windows Server 2003 R2 Datacenter Edition (32-Bit x86)
  4. Microsoft Windows Server 2003 R2 Standard x64 Edition
  5. Microsoft Windows Server 2003 R2 Enterprise x64 Edition
  6. Microsoft Windows Server 2003 R2 Datacenter x64 Edition
  7. Microsoft Windows Server 2003, Standard x64 Edition
  8. Microsoft Windows Server 2003, Enterprise x64 Edition
  9. Microsoft Windows Server 2003, Datacenter x64 Edition
  10. Microsoft Windows Server 2003 Service Pack 1, when used with:
    Microsoft Windows Server 2003, Standard Edition (32-bit x86)
    Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
    Microsoft Windows Server 2003, Web Edition
    Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
    Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
  11. Microsoft Windows Server 2003, Standard Edition (32-bit x86)
  12. Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  13. Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
  14. Microsoft Windows Server 2003, Web Edition
  15. Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
  16. Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  17. Microsoft Windows Small Business Server 2003 Standard Edition
  18. Microsoft Windows 2000 Service Pack 4, when used with:
    Microsoft Windows 2000 Datacenter Server
    Microsoft Windows 2000 Advanced Server
    Microsoft Windows 2000 Server
  19. Microsoft Windows 2000 Professional Edition, when used with:
    Microsoft Windows 2000 Professional Edition
  20. Microsoft Small Business Server 2000 Standard Edition

Tuyet Phan