Microsoft WPAD Elevation of Privilege Vulnerabilities
Last Update Date:
15 Jun 2016 17:47
Release Date:
15 Jun 2016
3868
Views
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
- Windows WPAD Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists in Microsoft Windows when the Web Proxy Auto Discovery (WPAD) protocol falls back to a vulnerable proxy discovery process. An attacker who successfully exploited this vulnerability could bypass security and gain elevated privileges on a targeted system. - Windows WPAD Proxy Discovery Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists when Microsoft Windows improperly handles certain proxy discovery scenarios using the Web Proxy Auto Discovery (WPAD) protocol method. An attacker who successfully exploited the vulnerability could potentially access and control network traffic for which the attacker does not have sufficient privileges. The update addresses the vulnerability by correcting WPAD automatic proxy detection in Windows.
Impact
- Elevation of Privilege
System / Technologies affected
- Microsoft Windows Vista
- Microsoft Windows Server 2008
- Microsoft Windows 7
- Microsoft Windows Server 2008 R2
- Microsoft Windows 8.1
- Microsoft Windows Server 2012 and Windows Server 2012 R2
- Microsoft Windows RT 8.1
- Microsoft Windows 10
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS16-077
Vulnerability Identifier
Source
Related Link
Share with