Unrated severityNVD Advisory· Published Mar 11, 2009· Updated Jun 16, 2026
CVE-2009-0094
CVE-2009-0094
Description
The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2003:*:sp1:itanium:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_server_2008:*:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2008:*:*:x64:*:*:*:*:*
- Range: 2000 SP4, Server 2003 SP1 and SP2
Patches
Vulnerability mechanics
References
10- www.us-cert.gov/cas/techalerts/TA09-069A.htmlnvdUS Government Resource
- blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspxnvd
- osvdb.org/52520nvd
- secunia.com/advisories/34217nvd
- support.avaya.com/elmodocs2/security/ASA-2009-083.htmnvd
- www.securityfocus.com/bid/34013nvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2009/0661nvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-008nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6117nvd
News mentions
0No linked articles in our index yet.