← Back

CVE-2009-0094

nvd nist
Published: Mar 11, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.5
Vector
AV:N/AC:L/Au:S/C:N/I:P/A:P
Exploitability: 8.0 / Impact: 4.9
Source: NVD

Description

The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.

Affected (7)

3 products
Windows 2000
Windows Server 2003
Windows Server 2008
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Microsoft
All versions
All versions
All versions
All versions
Microsoft
All versions
All versions

References (20)

Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.