CVE-2023-50868
published 2024-02-14CVE-2023-50868: The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU…
PriorityP356high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
81.73%
99.6th percentile
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cz.nic | knot-resolver | >= 0 < 5.6.0-1+deb12u1 | 5.6.0-1+deb12u1 |
| cz.nic | knot-resolver | >= 0 < 5.7.1-1 | 5.7.1-1 |
| cz.nic | knot-resolver | >= 0 < 5.7.1-1 | 5.7.1-1 |
| debian | bind9 | < bind9 1:9.18.24-1 (bookworm) | bind9 1:9.18.24-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | dnsjava | < bind9 1:9.18.24-1 (bookworm) | bind9 1:9.18.24-1 (bookworm) |
| debian | dnsmasq | < bind9 1:9.18.24-1 (bookworm) | bind9 1:9.18.24-1 (bookworm) |
| debian | knot-resolver | < bind9 1:9.18.24-1 (bookworm) | bind9 1:9.18.24-1 (bookworm) |
| debian | pdns-recursor | < bind9 1:9.18.24-1 (bookworm) | bind9 1:9.18.24-1 (bookworm) |
| debian | systemd | < bind9 1:9.18.24-1 (bookworm) | bind9 1:9.18.24-1 (bookworm) |
| debian | unbound | < bind9 1:9.18.24-1 (bookworm) | bind9 1:9.18.24-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| isc | bind | >= 9.0.0 < 9.16.48 | 9.16.48 |
| isc | bind | >= 9.18.0 < 9.18.24 | 9.18.24 |
| isc | bind | >= 9.18.11 < 9.18.24 | 9.18.24 |
| isc | bind | >= 9.19.0 < 9.19.21 | 9.19.21 |
| isc | bind | >= 9.9.3 < 9.16.48 | 9.16.48 |
| isc | bind9 | >= 0 < 1:9.16.48-1 | 1:9.16.48-1 |
| isc | bind9 | >= 0 < 1:9.18.24-1 | 1:9.18.24-1 |
| isc | bind9 | >= 0 < 1:9.19.21-1 | 1:9.19.21-1 |
| isc | bind9 | >= 0 < 1:9.19.21-1 | 1:9.19.21-1 |
| isc | bind9 | >= 0 < 1:9.16.48-0ubuntu0.20.04.1 | 1:9.16.48-0ubuntu0.20.04.1 |
| isc | bind9 | >= 0 < 1:9.18.18-0ubuntu0.22.04.2 | 1:9.18.18-0ubuntu0.22.04.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor DNS resolvers for anomalous CPU spikes triggered by high volumes of DNSSEC NSEC3 responses; the attack can create a 72x increase in CPU instruction count even when resolvers follow RFC5155 iteration limits. ↗
- →Alert on packet loss rates of 2.7%–30% on benign DNS traffic when a resolver is receiving approximately 150 or more malicious NSEC3 records per second, which is a threshold indicative of an active NSEC3-encloser attack. ↗
- →Inspect NSEC3 records in DNSSEC responses for use of salt combined with high hash iteration counts; the presence of salt increases resolver CPU load by ~30% and is a key attack amplifier. ↗
- →Flag DNSSEC-signed zones using high hash iteration counts in NSEC3 records as potential abuse vectors; 77% of NSEC3 domains observed in the wild use a high number of hash iterations. ↗
- →The attack vector is a random subdomain (NXDOMAIN) flood targeting DNSSEC-validating resolvers; queries for non-existent subdomains force the resolver to process crafted NSEC3 closest-encloser proof records with expensive SHA-1 hash iterations. ↗
- ·The attack is effective even when resolvers comply with RFC5155 iteration count recommendations; simply enforcing RFC5155 limits is insufficient to fully mitigate CPU exhaustion. ↗
- ·The attack requires a relatively high query rate to cause significant packet loss, and the impact on traffic loss is relatively low compared to other DNS attacks. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
dnsmasq vulnerabilities
osv·2024-04-24·CVSS 7.5
CVE-2023-50387 [HIGH] dnsmasq vulnerabilities
dnsmasq vulnerabilities
USN-6657-1 fixed several vulnerabilities in Dnsmasq. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Dnsmasq icorrectly handled validating DNSSEC messages. A remote
attacker could possibly use this issue to cause Dnsmasq to consume
resources, leading to a denial of service. (CVE-2023-50387)
It was discovered that Dnsmasq incorrectly handled preparing an NSEC3
closest encloser proof. A remote attacker could possibly use this issue to
cause Dnsmasq to consume resources, leading to a denial of service.
(CVE-2023-50868)
It was discovered that Dnsmasq incorrectly set the maximum EDNS.0 UDP
packet size as required by DNS
OSV
bind9 vulnerabilities
osv·2024-04-09·CVSS 7.5
CVE-2023-50387 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Bind icorrectly handled validating DNSSEC messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-50387)
It was discovered that Bind incorrectly handled preparing an NSEC3 closest
encloser proof. A remote attacker could possibly use this issue to cause
Bind to consume resources, leading to a denial of service. (CVE-2023-50868)
OSV
unbound vulnerabilities
osv·2024-02-28·CVSS 7.5
CVE-2023-50387 [HIGH] unbound vulnerabilities
unbound vulnerabilities
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Unbound incorrectly handled validating DNSSEC messages. A remote
attacker could possibly use this issue to cause Unbound to consume
resources, leading to a denial of service. (CVE-2023-50387)
It was discovered that Unbound incorrectly handled preparing an NSEC3
closest encloser proof. A remote attacker could possibly use this issue to
cause Unbound to consume resources, leading to a denial of service.
(CVE-2023-50868)
OSV
dnsmasq vulnerabilities
osv·2024-02-26·CVSS 7.5
CVE-2023-50387 [HIGH] dnsmasq vulnerabilities
dnsmasq vulnerabilities
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Dnsmasq icorrectly handled validating DNSSEC messages. A remote
attacker could possibly use this issue to cause Dnsmasq to consume
resources, leading to a denial of service. (CVE-2023-50387)
It was discovered that Dnsmasq incorrectly handled preparing an NSEC3
closest encloser proof. A remote attacker could possibly use this issue to
cause Dnsmasq to consume resources, leading to a denial of service.
(CVE-2023-50868)
It was discovered that Dnsmasq incorrectly set the maximum EDNS.0 UDP
packet size as required by DNS Flag Day 2020. This issue only affected
Ubuntu 23.10. (CVE-2023-28450)
OSV
bind9 vulnerabilities
osv·2024-02-19·CVSS 7.5
CVE-2023-4408 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Shoham Danino, Anat Bremler-Barr, Yehuda Afek, and Yuval Shavitt discovered
that Bind incorrectly handled parsing large DNS messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-4408)
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Bind icorrectly handled validating DNSSEC messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-50387)
It was discovered that Bind incorrectly handled preparing an NSEC3 closest
encloser proof. A remote attacker could possibly use this issue to cause
Bind to consume resources, leading to a denial of service. (CVE-2023-50868)
It was discovered
OSV
CVE-2023-50868: The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of ser
osv·2024-02-14·CVSS 7.5
CVE-2023-50868 [HIGH] CVE-2023-50868: The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of ser
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
GHSA
GHSA-pv4h-p8jr-6cv2: The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of ser
ghsa_unreviewed·2024-02-14
CVE-2023-50868 [HIGH] CWE-400 GHSA-pv4h-p8jr-6cv2: The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of ser
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
OSV
bind9 vulnerabilities
osv·2024-02-13·CVSS 7.5
CVE-2023-4408 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Shoham Danino, Anat Bremler-Barr, Yehuda Afek, and Yuval Shavitt discovered
that Bind incorrectly handled parsing large DNS messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-4408)
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Bind icorrectly handled validating DNSSEC messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-50387)
It was discovered that Bind incorrectly handled preparing an NSEC3 closest
encloser proof. A remote attacker could possibly use this issue to cause
Bind to consume resources, leading to a denial of service. (CVE-2023-50868)
It was discovered
Oracle
Oracle Oracle Communications Risk Matrix: Platform (BIND) — CVE-2023-50868
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2023-50868 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (BIND) — CVE-2023-50868
Oracle Oracle Communications Risk Matrix: Platform (BIND) vulnerability
CVE: CVE-2023-50868
CVSS: 7.5
Protocol: DNS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
CISA ICS
Siemens SINEC INS
cisa_ics·2024-11-14
Siemens SINEC INS
ICS Advisory
##
Siemens SINEC INS
Release DateNovember 14, 2024
Alert CodeICSA-24-319-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.9
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Authentication, Out-of-bounds Write, Ineffici
Microsoft
MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU
vendor_msrc·2024-06-11·CVSS 7.5
CVE-2023-50868 [HIGH] MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU
MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU
FAQ: Why is the MITRE Corporation the assigning CNA (CVE Numbering Authority)?
CVE-2023-50868 is regarding a vulnerability in DNSSEC validation where an attacker could exploit standard DNSSEC protocols intended for DNS integrity by using excessive resources on a resolver, causing a denial of service for legitimate users. MITRE created this CVE on their behalf.
Please see CVE-2023-50868 for more information.
Microsoft Windows: Microsoft Windows
MITRE Corporation: MITRE Corporation
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5039217
Ref
Ubuntu
Dnsmasq vulnerabilities
vendor_ubuntu·2024-04-24·CVSS 7.5
CVE-2023-50387 [HIGH] Dnsmasq vulnerabilities
Title: Dnsmasq vulnerabilities
Summary: Several security issues were fixed in Dnsmasq.
USN-6657-1 fixed several vulnerabilities in Dnsmasq. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Dnsmasq icorrectly handled validating DNSSEC messages. A remote
attacker could possibly use this issue to cause Dnsmasq to consume
resources, leading to a denial of service. (CVE-2023-50387)
It was discovered that Dnsmasq incorrectly handled preparing an NSEC3
closest encloser proof. A remote attacker could possibly use this issue to
cause Dnsmasq to consume resources, leading to a denial of service.
(CVE-2023-50868)
It was discovered that Dnsmasq incor
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2024-04-09·CVSS 7.5
CVE-2023-50387 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind could be made to crash if it received specially crafted
input.
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Bind icorrectly handled validating DNSSEC messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-50387)
It was discovered that Bind incorrectly handled preparing an NSEC3 closest
encloser proof. A remote attacker could possibly use this issue to cause
Bind to consume resources, leading to a denial of service. (CVE-2023-50868)
Instructions: In general, a standard system update will make all the necessary changes.
BSD
FreeBSD-SA-24:03.unbound: Multiple vulnerabilities in unbound
bsd_advisories·2024-03-28·CVSS 7.5
CVE-2023-50387 [HIGH] FreeBSD-SA-24:03.unbound: Multiple vulnerabilities in unbound
FreeBSD-SA-24:03.unbound Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in unbound
Category: contrib
Module: unbound
Announced: 2024-03-28
Affects: FreeBSD 13.2 and FreeBSD 14.0
Corrected: 2024-02-17 13:45:44 UTC (stable/14, 14.0-STABLE)
2024-03-28 05:06:26 UTC (releng/14.0, 14.0-RELEASE-p6)
2024-02-17 13:45:44 UTC (stable/13, 13.2-STABLE)
2024-03-28 05:07:55 UTC (releng/13.2, 13.2-RELEASE-p11)
CVE Name: CVE-2023-50387, CVE-2023-50868
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
Unbound is a validating, recursive, and caching DNS resolver.
II. Problem Description
The KeyTrap vulnerability (CVE-2023-50387) works by using a co
Ubuntu
Unbound vulnerabilities
vendor_ubuntu·2024-02-28·CVSS 7.5
CVE-2023-50868 [HIGH] Unbound vulnerabilities
Title: Unbound vulnerabilities
Summary: Several security issues were fixed in Unbound.
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Unbound incorrectly handled validating DNSSEC messages. A remote
attacker could possibly use this issue to cause Unbound to consume
resources, leading to a denial of service. (CVE-2023-50387)
It was discovered that Unbound incorrectly handled preparing an NSEC3
closest encloser proof. A remote attacker could possibly use this issue to
cause Unbound to consume resources, leading to a denial of service.
(CVE-2023-50868)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Dnsmasq vulnerabilities
vendor_ubuntu·2024-02-26·CVSS 7.5
CVE-2023-50387 [HIGH] Dnsmasq vulnerabilities
Title: Dnsmasq vulnerabilities
Summary: Several security issues were fixed in Dnsmasq.
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Dnsmasq icorrectly handled validating DNSSEC messages. A remote
attacker could possibly use this issue to cause Dnsmasq to consume
resources, leading to a denial of service. (CVE-2023-50387)
It was discovered that Dnsmasq incorrectly handled preparing an NSEC3
closest encloser proof. A remote attacker could possibly use this issue to
cause Dnsmasq to consume resources, leading to a denial of service.
(CVE-2023-50868)
It was discovered that Dnsmasq incorrectly set the maximum EDNS.0 UDP
packet size as required by DNS Flag Day 2020. This issue only affected
Ubuntu 23.10. (CVE-2023-28450)
Instructions: This update uses a n
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2024-02-19·CVSS 7.5
CVE-2023-50868 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Shoham Danino, Anat Bremler-Barr, Yehuda Afek, and Yuval Shavitt discovered
that Bind incorrectly handled parsing large DNS messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-4408)
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Bind icorrectly handled validating DNSSEC messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-50387)
It was discovered that Bind incorrectly handled preparing an NSEC3 closest
encloser proof. A remote attacker could possibly use this issue to cause
Bind to consume resources, leading
BSD
OpenBSD 7.3 Errata 026: SECURITY FIX
bsd_advisories·2024-02-13·CVSS 7.5
CVE-2023-50387 [HIGH] OpenBSD 7.3 Errata 026: SECURITY FIX
OpenBSD 7.3 Errata 026: SECURITY FIX
026: SECURITY FIX: February 13, 2024
All architectures DNSSEC protocol vulnerabilities have been discovered that render various DNSSEC validators victims of Denial Of Service while trying to validate specially crafted DNSSEC responses. Fix CVE-2023-50387 and CVE-2023-50868 in unwind(8) and unbound(8).
Red Hat
bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources
vendor_redhat·2024-02-13·CVSS 7.5
CVE-2023-50868 [HIGH] CWE-400 bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources
bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
A flaw was found in bind9. By flooding a DNSSEC resolver with responses coming from a DNSEC-signed zone using NSEC3, an attacker can lead the targeted resolver to a CPU exhaustion, further leading to a Denial of Service on the targeted host.
This vulnerability applies only for systems where DNSSEC validation is enabled.
BSD
OpenBSD 7.4 Errata 013: SECURITY FIX
bsd_advisories·2024-02-13·CVSS 7.5
CVE-2023-50387 [HIGH] OpenBSD 7.4 Errata 013: SECURITY FIX
OpenBSD 7.4 Errata 013: SECURITY FIX
013: SECURITY FIX: February 13, 2024
All architectures DNSSEC protocol vulnerabilities have been discovered that render various DNSSEC validators victims of Denial Of Service while trying to validate specially crafted DNSSEC responses. Fix CVE-2023-50387 and CVE-2023-50868 in unwind(8) and unbound(8).
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2024-02-13·CVSS 7.5
CVE-2023-5517 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Shoham Danino, Anat Bremler-Barr, Yehuda Afek, and Yuval Shavitt discovered
that Bind incorrectly handled parsing large DNS messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-4408)
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Bind icorrectly handled validating DNSSEC messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-50387)
It was discovered that Bind incorrectly handled preparing an NSEC3 closest
encloser proof. A remote attacker could possibly use this issue to cause
Bind to consume resources, leading
Debian
CVE-2023-50868: bind9 - The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276...
vendor_debian·2023·CVSS 7.5
CVE-2023-50868 [HIGH] CVE-2023-50868: bind9 - The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276...
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Scope: local
bookworm: resolved (fixed in 1:9.18.24-1)
bullseye: resolved (fixed in 1:9.16.48-1)
forky: resolved (fixed in 1:9.19.21-1)
sid: resolved (fixed in 1:9.19.21-1)
trixie: resolved (fixed in 1:9.19.21-1)
No detection rules found.
No public exploits indexed.
Checkpoint
17th June – Threat Intelligence Report
blogs_checkpoint·2024-06-17
CVE-2024-30080 17th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th June, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
An attack targeting Snowflake customer databases, identified as the work of threat actor UNC5537, has led to significant data theft and extortion. UNC5537 used stolen Snowflake customer credentials, obtained mainly from infostealer malware to access and exfiltrate large volumes of data from Snowflake instances. The compromised
Tenable
Microsoft’s June 2024 Patch Tuesday Addresses 49 CVEs
blogs_tenable·2024-06-11
Microsoft’s June 2024 Patch Tuesday Addresses 49 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
The June 2024 Security Update Review
blogs_trendmicro·2024-06-11
The June 2024 Security Update Review
# The June 2024 Security Update Review
Get the June 2024 security update and review.
By: Dustin Childs
2024/06/11
Read time: ( words)
Save to Folio
Somehow, we’ve made it to the sixth patch Tuesday of 2024, and Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for June 2024
For June, Adobe released 10 patches addressing 165(!) CVEs in Adobe Cold Fusion, Photoshop, Experience Manager, Audition, Media Encoder, FrameMaker Publishing Server, Adobe Commerce, Substance 3D Stager, Creative Cloud Desktop, and Acrobat Android. The fix for Experience Ma
Qualys
Microsoft & Adobe June 2024 Patch Tuesday: Critical Updates & Fixes | Qualys
blogs_qualys·2024-06-11
Microsoft & Adobe June 2024 Patch Tuesday: Critical Updates & Fixes | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for June 2024
- Adobe Patches for June 2024
- Zero-day Vulnerability Patched in June Patch Tuesday Edition
- Critical Severity Vulnerability Patched in June Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
Microsoft’s June Patch Tuesday is here, bringing fixes for vulnerabilities impacting its multiple products. This month’s release highlights the ongoing battle against cybersecurity threats, from critical updates to important fixes. Let’s dive into the crucial
Qualys
Microsoft and Adobe Patch Tuesday, June 2024 Security Update Review
blogs_qualys·2024-06-11
Microsoft and Adobe Patch Tuesday, June 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for June 2024
Adobe Patches for June 2024
Zero-day Vulnerability Patched in June Patch Tuesday Edition
Critical Severity Vulnerability Patched in June Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
Microsoft’s June Patch Tuesday is here, bringing fixes for vulnerabilities impacting its multiple products. This month’s release highlights the ongoing battle against cybersecurity threats, from critical updates to important fixes. Let’s dive into the crucial insights fro
Trendmicro
The June 2024 Security Update Review
blogs_trendmicro·2024-06-11
The June 2024 Security Update Review
## The June 2024 Security Update Review
Get the June 2024 security update and review.
By: Dustin Childs 2024/06/11 Read time: ( words)
Save to Folio
Somehow, we’ve made it to the sixth patch Tuesday of 2024, and Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for June 2024
For June, Adobe released 10 patches addressing 165(!) CVEs in Adobe Cold Fusion, Photoshop, Experience Manager, Audition, Media Encoder, FrameMaker Publishing Server, Adobe Commerce, Substance 3D Stager, Creative Cloud Desktop, and Acrobat Android. The fix for Experience Ma
Crowdstrike
June 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] June 2024 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
June 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] June 2024 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
Attacking with Something That Does Not Exist: 'Proof of Non-Existence' Can Exhaust DNS Resolver CPU
arxiv_fulltext·2024-06-17·CVSS 7.5
[HIGH] Attacking with Something That Does Not Exist: 'Proof of Non-Existence' Can Exhaust DNS Resolver CPU
Attacking with Something That Does Not Exist:
`Proof of Non-Existence' Can Exhaust DNS Resolver CPU
,
,
[* ]Olivia Gruza
[* ]Elias Heftrig
[* ]Oliver Jacobsen
[* ]Haya Schulmann
[* ]Niklas Vogel
[* ]Michael Waidner
[*]National Research Center for Applied Cybersecurity ATHENE
[ ]Goethe-Universit\"at Frankfurt
[ ]Technische Universit\"at Darmstadt
[ ]Fraunhofer Institute for Secure Information Technology SIT
## Abstract
NSEC3 is a proof of non-existence in DNSSEC, which provides an authenticated assertion that a queried resource does not exist in the target domain. NSEC3 consists of alphabetically sorted hashed names before and after the queried hostname. To make dictionary attacks harder, the hash function can be applied in multiple iterations, which however also increases the load on
arXiv
Attacking with Something That Does Not Exist: 'Proof of Non-Existence' Can Exhaust DNS Resolver CPU
arxiv_cs_cr·2024-06-17·CVSS 7.5
[HIGH] Attacking with Something That Does Not Exist: 'Proof of Non-Existence' Can Exhaust DNS Resolver CPU
Attacking with Something That Does Not Exist: 'Proof of Non-Existence' Can Exhaust DNS Resolver CPU
NSEC3 is a proof of non-existence in DNSSEC, which provides an authenticated assertion that a queried resource does not exist in the target domain. NSEC3 consists of alphabetically sorted hashed names before and after the queried hostname. To make dictionary attacks harder, the hash function can be applied in multiple iterations, which however also increases the load on the DNS resolver during the computation of the SHA-1 hashes in NSEC3 records. Concerns about the load created by the computation of NSEC3 records on the DNS resolvers were already considered in the NSEC3 specifications RFC5155 and RFC9276. In February 2024, the potential of NSEC3 to exhaust DNS resolvers' resources was assig
http://www.openwall.com/lists/oss-security/2024/02/16/2http://www.openwall.com/lists/oss-security/2024/02/16/3https://access.redhat.com/security/cve/CVE-2023-50868https://bugzilla.suse.com/show_bug.cgi?id=1219826https://datatracker.ietf.org/doc/html/rfc5155https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.htmlhttps://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1https://kb.isc.org/docs/cve-2023-50868https://lists.debian.org/debian-lts-announce/2024/02/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.htmlhttps://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/https://security.netapp.com/advisory/ntap-20240307-0008/https://www.isc.org/blogs/2024-bind-security-release/http://www.openwall.com/lists/oss-security/2024/02/16/2http://www.openwall.com/lists/oss-security/2024/02/16/3https://access.redhat.com/security/cve/CVE-2023-50868https://bugzilla.suse.com/show_bug.cgi?id=1219826https://datatracker.ietf.org/doc/html/rfc5155https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.htmlhttps://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1https://kb.isc.org/docs/cve-2023-50868https://lists.debian.org/debian-lts-announce/2024/02/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2024/11/msg00035.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/https://lists.fedoraproject.org/archives/list/[email protected]/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/https://lists.fedoraproject.org/archives/list/[email protected]/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.htmlhttps://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/https://security.netapp.com/advisory/ntap-20240307-0008/https://www.isc.org/blogs/2024-bind-security-release/
2024-02-14
Published