Microsoft warned companies on Monday that a flaw in the way Windows searches for Web proxies could allow an attacker the ability to reroute traffic through a malicious server.
The security issues occur when a Windows computer attempts to find a proxy server using Microsoft’s Web Proxy Automatic Discovery (WPAD) technology and the organization’s domain name starts at the third level or deeper, such as somecompany.co.jp, the software giant stated in an advisory. The WPAD search first attempts to find the server using the fully-qualified domain name (FQDN), and if it doesn’t find the server will try the next higher level of the domain name. For example, a search for a proxy server in somecompany.co.jp will look for servername.somecompany.co.jp and then move on to servername.co.jp, which could be a malicious server outside the company’s network.
“At this time, we are not aware of attacks attempting to use the reported vulnerability, but we will continue to track this issue,” Tim Rains, a spokesman for the Microsoft Security Response Center, said on the teams’ blog. “The advisory contains several mitigations that customers can use to help protect themselves from attackers.”
