# ISC BIND DoS Flaw Prompts Patch Advisory

Published: 2023-01-25 · Severity: low · Sectors: telecommunications, infrastructure
Canonical: https://vorant.io/reports/836a3838-77e8-5f10-bc60-1e02737b27fd/isc-bind-dos-flaw-prompts-patch-advisory

> Japan's IPA warns of a remote DoS vulnerability in ISC BIND DNS software, urging admins to update, though no active exploitation has been observed.

The Information-technology Promotion Agency (IPA) of Japan issued an advisory regarding a denial-of-service vulnerability in BIND, the widely used DNS server software maintained by ISC. If exploited, the flaw could allow an attacker to cause unintended service outages on affected DNS servers.

As of the advisory date, no in-the-wild exploitation has been confirmed, but IPA cautions that future attacks are possible given the vulnerability's public disclosure. ISC and various vendors distributing BIND have released updated versions addressing the issue, and administrators are urged to apply these patches promptly to avoid potential service disruption.

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/alert20230126.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/836a3838-77e8-5f10-bc60-1e02737b27fd/isc-bind-dos-flaw-prompts-patch-advisory.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
