# BIND DNS servers face remote DoS vulnerability

Published: 2023-01-25 · Severity: high
Canonical: https://vorant.io/reports/edf4b46c-3ce3-439e-b1d5-a7ea30cd5be1/bind-dns-servers-face-remote-dos-vulnerability

> BIND DNS server vulnerability allows remote denial-of-service attacks; patches available, no active exploitation observed yet.

Japan's IPA (Information-technology Promotion Agency) issued an advisory regarding a remote denial-of-service vulnerability in BIND DNS servers. Exploitation of this flaw could lead to unintended service interruptions. The advisory notes that no attacks exploiting this vulnerability have been confirmed at the time of publication, but emphasizes the potential for future exploitation.

ISC and various vendors have released updated versions of BIND that address this vulnerability. DNS server administrators are urged to apply the available patches promptly to mitigate the risk of service disruption.

The advisory was published on January 26, 2023, and directs administrators to contact ISC or their respective vendors for patch deployment. IPA's Security Center clarifies that they cannot provide support for individual system configurations and recommends consulting product vendors for specific implementation guidance.

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/alert20230126.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/edf4b46c-3ce3-439e-b1d5-a7ea30cd5be1/bind-dns-servers-face-remote-dos-vulnerability.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
