Hey All,

I heard back from MSFT and this was the intended functionality of the patch.

There are important reasons why this path was chosen: it is not possible to tell legitimate WPAD entries from illegitimate ones that were loaded by attackers. Hence our need to accept an already "existent" entry as being valid.
It sounds like functionality beat security here... and that sounds like an issue to me.

In my attempts to raise awareness to this issue, I've posted another blog post -- http://blog.ncircle.com/blogs/vert/a..._security.html