CVE-2020-8624: update-policy rules of type "subdomain" are enforced incorrectly
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to update other contents of the zone.
Other sources
ISC BIND could allow a remote authenticated attacker to bypass security restrictions, caused by the failure to properly enforce the update-policy rules of type "subdomain". By sending a specially-crafted request, an attacker could exploit this vulnerability to update other contents of the zone.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-8624?
CVE-2020-8624 is a vulnerability in ISC BIND that could allow a remote authenticated attacker to bypass security restrictions.
Which versions of BIND are affected by CVE-2020-8624?
Versions 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, and 9.17.0 -> 9.17.3 are affected.
How can an attacker exploit CVE-2020-8624?
An attacker who has been granted privileges to change a specific subset of the zone's content could exploit this vulnerability.
What is the severity of CVE-2020-8624?
The severity of CVE-2020-8624 is high with a CVSS score of 4.3.
How do I fix CVE-2020-8624?
To fix CVE-2020-8624, upgrade BIND to a version that is not affected by the vulnerability.