AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-5355

MEDIUM · CVSS 5.8 EPSS 16.63%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-12-05 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2007-5355
Severity
MEDIUM
CVSS
5.8
EPSS
16.63%
Microsoft

Original Filing — NVD Description

The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Internet Explorer 6 and 7, when a primary DNS suffix with three or more components is configured, resolves an unqualified wpad hostname in a second-level domain outside this configured DNS domain, which allows remote WPAD servers to conduct man-in-the-middle (MITM) attacks.