CVE-2015-5477 is a reachable assertion vulnerability in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3. Improper handling of TKEY queries permits a remotely supplied crafted query to trigger a REQUIRE assertion failure, causing the named daemon to exit. Both recursive and authoritative BIND name servers are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit auxiliary module (modules/auxiliary/dos/dns/bind_tkey.rb) that exploits CVE-2015-5477, a denial-of-service vulnerability in ISC BIND9 DNS servers. The module constructs and sends a malformed DNS TKEY query packet to the target's UDP port 53. If the target is running a vulnerable version of BIND9, the server will crash with a REQUIRE assertion failure, resulting in a denial of service. The exploit allows optional spoofing of the source address. The code is written in Ruby and leverages Metasploit's auxiliary and UDP scanner modules. No hardcoded IPs or domains are present; the target is specified by the user. The repository is operational and suitable for use in testing or attacking vulnerable BIND9 instances.
This repository contains a proof-of-concept (PoC) exploit for CVE-2015-5477, a denial-of-service vulnerability in ISC BIND9's TKEY record processing. The repository consists of a single C source file (tkill.c) and a README.md. The exploit works by sending a specially crafted UDP packet (the 'dospacket') to the target's DNS service (port 53), which triggers an assertion failure and crashes the server. The code supports both IPv4 and IPv6, and can target multiple hosts or IPs specified on the command line. The exploit first sends a version query to check if the server is up, then sends the DoS packet, and waits to see if the server becomes unresponsive. The payload is hardcoded in the source and is not customizable. The exploit is cross-platform and can be compiled and run on Linux, macOS, and Windows (with appropriate toolchains). The README provides usage instructions and background on the vulnerability. The only notable endpoint in the code is a reference URL embedded in the DoS packet, which points to the exploit's GitHub repository.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.