Impact
During zone processing, the checkwildcard() function may incorrectly accept an out‑of‑zone NSEC record as proof that no wildcard domain exists. The flaw allows an attacker who controls the same or a higher level zone to inject such a record, thereby masking the presence of a legitimate wildcard record. This can affect DNS resolution for sub‑domains and undermine security controls that rely on wildcard entries.
Affected Systems
The vulnerability affects ISC BIND 9, specifically versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and the corresponding -S1 builds (9.11.3‑S1 through 9.18.50‑S1 and 9.20.9‑S1 through 9.20.27‑S1).
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Exploitation would require an attacker to supply a suitable NSEC record in a zone they control or influence, and the named resolver would then ignore the wildcard. Therefore the attack vector is inferred to be a controlled DNS zone rather than a remote network attack. Organizations should treat this as a moderate risk until the solution is applied.
OpenCVE Enrichment