The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Base Score: 7.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Oct 1, 2024 | Jan 16, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 15, 2017 | Jun 15, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Suse | — | Upgrade libdns1605Upgrade libns1604Upgrade libbind9-1600Upgrade libirs1601Upgrade libisc1606Upgrade libisccfg160Upgrade libdns169Upgrade bind-docUpgrade libbind9-160Upgrade liblwres160Upgrade libirs160Upgrade bind-develUpgrade libisc166Upgrade libisccc1600Upgrade libisccc160Upgrade python3-bindUpgrade bind-utilsUpgrade libirs-develUpgrade libisccfg1600Upgrade bindUpgrade bind-chrootenv | May 20, 2018 | May 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub