Microsoft confirms man-in-the-middle WPAD vulnerability
Following the public release of a serious flaw in the way Windows resolves hostnames that do not include a fully-qualified domain name (FQDN), Microsoft has issued a security advisory to acknowledge the issue and offer pre-patch workarounds.
Redmond’s advisory comes more than two weeks after hacker Beau Butler discussed the issue at the Kiwicon 2007 event in New Zealand. The issue affects Windows 2000, Windows XP, Windows Server 2003 and Windows Vista users. It also relates to all versions of Internet Explorer, including IE 7 for Windows Vista.