External risk intelligence

BIND Denial of Service via TKEY Queries.

CVE advisoryKnown Exploit

CVE-2015-5477

ISC BIND is the most widely used DNS server software on the internet. Authoritative and recursive DNS servers are designed to be public-facing by default to resolve queries for domains or provide recursive resolution services to clients, making this component a standard, internet-exposed network edge service.

Denial of Service

Isc Bind

9.9.7 and earlier9.10.2 and earlier

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a denial-of-service vulnerability in ISC BIND, a widely used DNS server software. The vulnerability, triggered by specific queries, could allow attackers to cause the DNS service to exit, disrupting operations. The primary concern is confirming relevance and exposure, as BIND is a critical component for domain name resolution.

  • BIND servers can be crashed remotely.
  • Affects critical internet domain name resolution.
  • Confirm if your BIND services are exposed.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted TKEY queries to a vulnerable BIND server. Since BIND is a widely used DNS server, it is often exposed to the internet, allowing remote attackers to reach it without any special access. When the server processes these malicious queries, it can lead to a denial-of-service condition by causing the DNS daemon to exit.

  • Network access required.
  • Triggered by TKEY queries.
  • Leads to denial of service.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, remote attackers could cause denial of service by sending TKEY queries to ISC BIND. This could lead to a REQUIRE assertion failure and the daemon exiting, disrupting DNS resolution services.

  • DNS server availability.
  • Exposure via crafted TKEY queries.
  • Service interruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

This high-severity vulnerability in ISC BIND impacts the reliability of DNS resolution services, potentially causing widespread denial of service. The primary responsibility for addressing this issue typically lies with the infrastructure or platform teams managing DNS services. The immediate first step is to inventory all instances of affected BIND versions, assess their network exposure and criticality, and identify the system owners responsible for remediation planning.

  • Infrastructure or platform teams should own the issue.
  • Verify BIND's network exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ISC BIND?

ISC BIND is widely used open-source software that implements the Domain Name System (DNS) protocols. It functions as a foundational internet service, acting as either an authoritative server that provides DNS data for domains or a recursive resolver that helps clients find domain information. Because it is essential for translating human-readable names into network addresses, it is a primary component of network infrastructure.

What does CVE-2015-5477 mean for BIND stability?

This vulnerability, classified as CWE-617 (Reachable Assertion) and CWE-19 (Data Processing Errors), allows an attacker to crash the BIND daemon. When the software receives a specifically malformed TKEY query, it triggers an assertion failure. This forced shutdown causes a denial-of-service condition, stopping the server from performing its critical role in domain name resolution.

How do attackers trigger this vulnerability?

An attacker triggers this bug by sending a specially crafted TKEY query to a vulnerable BIND server over the network. The vulnerability exists specifically in how the daemon handles these TKEY query packets. It is not triggered by standard DNS queries, normal web traffic, or administrative commands that do not involve this specific, malformed TKEY request structure.

Why is internet-facing BIND at risk?

Halo Surface Signal notes that BIND is the most widely used DNS software and is often deployed at the network edge to handle public queries. Because the vulnerability is remotely exploitable without authentication, any BIND server exposed directly to the internet is a potential target for attackers seeking to disrupt DNS availability.

What are the first steps to secure my BIND installation?

The priority is to identify all BIND instances within your environment to determine which versions are running. Once you have an inventory, confirm the network exposure and criticality of those systems. Infrastructure teams should prioritize patching or upgrading BIND to a version that contains the fix to ensure the service can correctly process TKEY queries without crashing.

References