The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Base Score: 7.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Oct 1, 2024 | Jan 16, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 15, 2017 | Jun 15, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Suse | — | Upgrade libns1604Upgrade libbind9-160Upgrade libirs1601Upgrade libbind9-1600Upgrade libisccfg160Upgrade libisc1606Upgrade libdns1605Upgrade libdns169Upgrade liblwres160Upgrade bind-docUpgrade libirs160Upgrade bindUpgrade bind-develUpgrade libisccfg1600Upgrade libisc166Upgrade libirs-develUpgrade bind-utilsUpgrade python3-bindUpgrade bind-chrootenvUpgrade libisccc160Upgrade libisccc1600 | May 20, 2018 | May 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub