In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to update other contents of the zone.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/fokypoky/places-list
- https://github.com/krlabs/dnsbind-vulnerabilities
- https://github.com/psmedley/bind-os2