Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

ISC BIND Vulnerability (CVE‑2015‑5477) Allows Remote Denial‑of‑Service via TKEY Queries

A data‑processing error in ISC BIND can be triggered by malicious TKEY queries, causing the DNS service to crash. The issue highlights the need for continuous patch management and auditable evidence of service‑availability controls.

LiveThreat™ Intelligence · 📅 October 09, 2026· 📰 nvd.nist.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
nvd.nist.gov

CVE-2015-5477: ISC BIND Data‑Processing Errors Enable Remote DoS via TKEY Queries

What It Is – ISC BIND (the widely deployed DNS server) contains a data‑processing flaw that can be triggered by specially‑crafted TKEY queries. The flaw allows a remote, unauthenticated attacker to crash the name service, resulting in a denial‑of‑service condition.

Exploitability – The vulnerability is exploitable over the network without credentials. No public exploit code has been released, but the attack vector is trivial to construct. CVSS v3.1 base score is 5.3 (Moderate).

Affected Products – ISC BIND versions prior to the patch released in 2015 (all supported releases at the time).

Why It Matters for Trust & Control Assurance

  • Continuous monitoring of DNS health and patch status provides auditable evidence that the service‑availability control is being exercised.
  • Demonstrating timely remediation of known flaws satisfies the “incident response and service continuity” control objective that underpins many frameworks (e.g., NIST CSF 2.0).
  • A defensible audit trail of vulnerability management helps enterprise buyers verify that the organization can maintain the availability of critical infrastructure.

Recommended Actions

  • Apply the ISC‑provided patch or upgrade to the latest BIND release that includes the fix.
  • Verify that DNS logging is enabled and that alerts fire on abnormal TKEY query volumes.
  • Incorporate the patch‑deployment step into your change‑management workflow and retain evidence of completion for audit purposes.
  • Conduct a post‑remediation DoS test to confirm the service remains resilient.

Source: CISA KEV – CVE‑2015‑5477

📰 Original Source
https://nvd.nist.gov/vuln/detail/CVE-2015-5477 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →