The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Base Score: 7.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Oct 1, 2024 | Jan 16, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 15, 2017 | Jun 15, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Suse | — | Upgrade libbind9-160Upgrade bind-docUpgrade libdns1605Upgrade libns1604Upgrade libisc1606Upgrade liblwres160Upgrade libbind9-1600Upgrade libisccfg160Upgrade libirs1601Upgrade libdns169Upgrade libirs160Upgrade bind-develUpgrade libisccc1600Upgrade libisccc160Upgrade bind-chrootenvUpgrade bind-utilsUpgrade libirs-develUpgrade libisccfg1600Upgrade python3-bindUpgrade libisc166Upgrade bind | May 20, 2018 | May 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub