Remote denial of service in ISC BIND via TKEY queries
CISA: ISC BIND Data Processing Errors Vulnerability
CVSS 3.1
7.5high
EPSS
91%p100
Published
()
KEV added
AI analysis
A flaw in named, the DNS server in ISC BIND, lets a remote attacker crash the daemon by sending TKEY queries that trigger a REQUIRE assertion failure and force the process to exit. It is a data-processing error that reaches an assertion, needs no authentication or user interaction, and affects availability only. ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 are affected. The issue is rated CVSS 3.1 7.5 (high), with an EPSS of about 91 percent. CISA lists it in the Known Exploited Vulnerabilities catalog, so exploitation in the wild is confirmed; ransomware use is unknown and no public proof-of-concept is recorded in the supplied data.
What to do: Upgrade named to ISC BIND 9.9.7-P2 or later on the 9.9 branch, or 9.10.2-P3 or later on the 9.10 branch, and move to a currently supported BIND release because these 2015 branches are long obsolete. Prioritize internet-exposed resolvers and authoritative servers under CISA BOD 26-04, and stop using the product if a fix cannot be applied. After patching, review logs for unexpected named exits or REQUIRE assertion failures tied to TKEY queries.
Affected
ISC BIND
9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3
Estimated exposure
masson the order of 100,000–1,000,000+ DNS server installations — BIND 9 has long been the dominant authoritative and recursive DNS implementation; public nameserver surveys and internet scans have repeatedly found it on a large share of DNS servers, which supports an order-of-magnitude estimate of well…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
CISA Known Exploited Vulnerability
Affected
ISC BIND
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Joint advisory says Integrity Technology Group-enabled Chinese actors steal data from critical infrastructure using botnets and hands-on hacking.
CISA, the FBI, the NSA, and partner agencies issued joint advisory AA26-281A on Chinese government-linked actors enabled by Integrity Technology Group. The actors combine automated scanning, large-scale botnets, cross-site scripting, password spraying, and hands-on exploitation, including against Microsoft Exchange, to steal data. They persist through VPN software and use scripts to exfiltrate emails and credentials, targeting US critical infrastructure and organizations in Southeast Asia, Africa, and North America. Defenders are urged to hunt for compromise, disable unused services, sanitize web inputs, require MFA, and patch listed vulnerabilities.
FBI and six countries say China-linked Integrity Technology Group stole emails and shared them via a third-party portal.
On October 8, the FBI and agencies in six other countries said hackers tied to China's Integrity Technology Group stole email from government, law enforcement, healthcare, and religious organizations since at least mid-January 2021. The actors scanned sites with tools including MicroScan, which holds more than 1,300 scripts, guessed Microsoft 365 and Exchange passwords, copied mailboxes, and run a web app that gives unnamed third parties access to stolen email. The joint advisory lists eight exploited flaws—CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, and CVE-2023-22894—and says five were newly added to CISA's KEV catalog. The activity is consistent with Flax Typhoon, Ethereal Panda, and RedJuliett; the U.S. and UK have sanctioned the company, previously linked to the Raptor Train botnet of more than 200,000 devices.