← Blog · · df00tech

CISA Adds 2015 ISC BIND DoS Flaw (CVE-2015-5477) to KEV — Active Exploitation Confirmed

breaking kev ISC CVE-2015-5477

CISA has added CVE-2015-5477, a data-processing error in ISC BIND, to its Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild.

What happened

According to ISC's advisory, BIND contains a flaw in how it processes TKEY queries, allowing a remote attacker to trigger a denial-of-service condition — typically a crash or assertion failure in the named process — without authentication. CISA's KEV listing confirms this vulnerability is being actively exploited, though the specific threat actors and campaigns are not disclosed. It is unknown whether known ransomware operators are using this flaw.

Why it matters

BIND is one of the most widely deployed DNS server implementations on the internet, running on authoritative and recursive resolvers across enterprise, ISP, and cloud environments. A successful exploit crashes the DNS service, which can cause outages for any infrastructure that depends on that resolver — potentially cascading to dependent applications, email, and internal name resolution. Because the vulnerability requires no authentication and is remotely triggerable via crafted DNS queries, exposed BIND instances are a straightforward target.

What defenders should watch for

  • Inventory BIND deployments and confirm they are running patched versions; this is an old (2015) flaw, so any still-vulnerable instance has likely missed over a decade of patching.
  • Monitor named process logs for crashes, restarts, or assertion failures correlated with incoming TKEY query traffic.
  • At the network layer, watch for anomalous volumes of TKEY-type DNS queries targeting authoritative or recursive resolvers.
  • Ensure BIND service monitoring/alerting exists for unexpected restarts, and that redundant/secondary DNS servers are in place to limit outage impact.
  • Restrict recursive/administrative DNS query exposure to trusted networks where operationally feasible.

Developing intel

This is a KEV-driven alert based on CISA's catalog addition; details on the specific exploitation campaign are not yet public. We will update as more information becomes available. Source: ISC Knowledgebase advisory AA-01272.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.