NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


IE7 Proxy Settings in 32-bit and 64-bit Windows Vista Offer an Open Avenue for Attacks

But there is a range of mitigations in place

By Marius Oiaga, Technology News Editor

4th of December 2007, 10:11 GMT

Adjust text size:



Enlarge picture
Internet Explorer 7, the browser version that ships by default as a component of both 32-bit and 64-bit Windows Vista operating system, can serve as an open avenue for attacks, provided that the necessary proxy settings are in place. Microsoft issued a security advisory, confirming the existence of a vulnerability in Web Proxy Auto-Discovery (WPAD). In the eventuality
of a successful exploit, the attacks could lead to information disclosure, Microsoft informed. However, IE7 in Vista is not the only browser impacted by the security flaw.

"(...) [The] vulnerability [is associated with] the way Microsoft Windows XP SP2, Windows Server 2003 SP1, Windows Server 2003 SP2 and Windows Vista find a Web Proxy Automatic Discovery (WPAD) server. This vulnerability also affects supported versions of Internet Explorer. At this time, we are not aware of attacks attempting to use the reported vulnerability, but we will continue to track this issue," explained Tim Rains, from the Security Response Communications Team, at Microsoft.

The Redmond company informed of several mitigation factors that when in place will protect end users from being exploited via attacks, which target the vulnerability in Web Proxy Auto-Discovery. For the most part, the added layers of protection simply involve specific proxy configurations, and nothing more. For example, having the 'Automatically Detect Settings' option in Internet Explorer disabled is a shield against the security hole.

Safe from attacks are the end users that have manually entered the proxy server data in IE. On top of these examples, Microsoft also informed that WPAD servers, proxy server settings via DHCP or DNS, DNS domain names functioning as second-level domain (SLD), with a top-level domain (TLD) on top, and the lack of a primary DNS suffix are all mitigations against the vulnerability. Otherwise, all users are impacted by the flaw.

"Microsoft is investigating new public reports of a vulnerability in the way Windows resolves hostnames that do not include a fully-qualified domain name (FQDN). The technology that the vulnerability affects is Web Proxy Auto-Discovery (WPAD). (...) Customers whose domain name begins in a third-level or deeper domain, or for whom the following mitigating factors do not apply, are at risk from this vulnerability," the Redmond company revealed.

TAGS:

IE7 | Windows Vista | FQDN | Web Proxy Auto-Discovery | vulnerability
Read by 4,711 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.7/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Five-Year-Old Windows Design Flaw Comes Back to Haunt Vista

New Version of Internet Explorer 7 for Windows XP SP2 Available for Download

Is Microsoft Getting Ready to Let the Internet Explorer 8 Genie Out of the Bottle?

Vista Still Breathing as XP Chokes on Latest Vulnerability

49 Versions of Internet Explorer from IE 1.0 to IE 7.0

If Piracy Is a Crime then Why Is Microsoft Protecting Windows Pirates?

Download Microsoft Security Releases ISO Image - November 2007

Two New Free Editions of Windows XP SP2 Available for Download

New Proof-of-Concept Trojan Preys on Windows Vista

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM