Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to the patched release most closely related to your current version of BIND. These can all be downloaded from http://www.isc.org/downloads. BIND 9 version 9.9.10-P1 BIND 9 version 9.10.5-P1 BIND 9 version 9.11.1-P1 BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers. BIND 9 version 9.9.10-S2 BIND 9 version 9.10.5-S2
Vendor Workaround
BIND installations on Windows are not at risk if the host file permissions prevent creation of a binary in a location where the service executor would run it instead of named.exe.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-12282 | The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1. |
No history.
Status: PUBLISHED
Assigner: isc
Published:
Updated: 2024-09-16T17:23:44.753Z
Reserved: 2016-12-02T00:00:00.000Z
Link: CVE-2017-3141
No data.
Status : Modified
Published: 2019-01-16T20:29:00.503
Modified: 2024-11-21T03:24:55.147
Link: CVE-2017-3141
OpenCVE Enrichment
No data.
EUVD