CISA Adds 2015 ISC BIND DoS Flaw (CVE-2015-5477) to KEV — Active Exploitation Confirmed
CISA has added CVE-2015-5477, a data-processing error in ISC BIND, to its Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild.
What happened
According to ISC's advisory, BIND contains a flaw in how it processes TKEY queries, allowing a remote attacker to trigger a denial-of-service condition — typically a crash or assertion failure in the named process — without authentication. CISA's KEV listing confirms this vulnerability is being actively exploited, though the specific threat actors and campaigns are not disclosed. It is unknown whether known ransomware operators are using this flaw.
Why it matters
BIND is one of the most widely deployed DNS server implementations on the internet, running on authoritative and recursive resolvers across enterprise, ISP, and cloud environments. A successful exploit crashes the DNS service, which can cause outages for any infrastructure that depends on that resolver — potentially cascading to dependent applications, email, and internal name resolution. Because the vulnerability requires no authentication and is remotely triggerable via crafted DNS queries, exposed BIND instances are a straightforward target.
What defenders should watch for
- Inventory BIND deployments and confirm they are running patched versions; this is an old (2015) flaw, so any still-vulnerable instance has likely missed over a decade of patching.
- Monitor
namedprocess logs for crashes, restarts, or assertion failures correlated with incoming TKEY query traffic. - At the network layer, watch for anomalous volumes of TKEY-type DNS queries targeting authoritative or recursive resolvers.
- Ensure BIND service monitoring/alerting exists for unexpected restarts, and that redundant/secondary DNS servers are in place to limit outage impact.
- Restrict recursive/administrative DNS query exposure to trusted networks where operationally feasible.
Developing intel
This is a KEV-driven alert based on CISA's catalog addition; details on the specific exploitation campaign are not yet public. We will update as more information becomes available. Source: ISC Knowledgebase advisory AA-01272.