NETBIOS: WPAD WINS Server Registration Information Disclosure

This signature detects attempts to register WPAD to the Windows Internet Name Service (WINS). A successful exploit can lead to information disclosure.

Extended Description

The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.

Affected Products

Microsoft windows_server_2003

Short Name
NETBIOS:WINS:ISATAP-INFO-DIS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
NETBIOS
Keywords
CVE-2009-0094 Disclosure Information Registration Server WINS WPAD
Release Date
06/14/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
Port
UDP/137
False Positive
Unknown
Vendors

Microsoft

CVSS Score

5.5

Found a potential security threat?