The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Base Score: 7.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Oct 1, 2024 | Jan 16, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 15, 2017 | Jun 15, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Suse | — | Upgrade libirs1601Upgrade libisc1606Upgrade libdns169Upgrade libns1604Upgrade bind-docUpgrade liblwres160Upgrade libdns1605Upgrade libbind9-160Upgrade libbind9-1600Upgrade libisccfg160Upgrade python3-bindUpgrade bind-develUpgrade libisc166Upgrade bind-utilsUpgrade libisccfg1600Upgrade libirs-develUpgrade libirs160Upgrade bind-chrootenvUpgrade libisccc160Upgrade libisccc1600Upgrade bind | May 20, 2018 | May 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub