CVE-2020-8617 is a remote denial of service vulnerability in ISC BIND, affecting versions 9.0.0 through 9.16.2 and several development and preview releases. The vulnerability arises from a logic error in the dns_tsig_verify() function in lib/dns/tsig.c, which can be exploited by sending a specially crafted TSIG resource record in a DNS query. This triggers an assertion failure in dns_tsig_sign(), causing the BIND server to exit. The flaw impacts both recursive and authoritative servers, and is present in almost all BIND installations due to default TSIG key configuration.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module: modules/auxiliary/dos/dns/bind_tsig_badtime.rb. The module exploits a logic error in the BIND DNS server (CVE-2020-8617) related to TSIG (Transaction Signature) validation. By sending a specially crafted DNS query with a TSIG record containing a bad time value, the module can trigger an assertion failure in the BIND server's tsig.c code, resulting in a denial of service (DoS) and potentially crashing the DNS service. The exploit is implemented in Ruby and leverages Metasploit's UDPScanner and Capture modules to send the malicious packet to the target's UDP port 53. The only notable endpoints are the UDP port 53 (standard DNS) and the use of the TSIG key name 'local-ddns' in the payload. The module is a proof-of-concept (POC) for the vulnerability and does not provide post-exploitation capabilities.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2020-8617, a vulnerability in ISC BIND. The repository includes a Dockerfile to build and run a vulnerable BIND 9.12.4 DNS server with custom configuration and zone files. The main exploit script, exploit.py, uses Python and the Scapy library to craft and send a DNS query with a malformed TSIG (Transaction Signature) record to the local DNS server (127.0.0.1:53). The exploit demonstrates the vulnerability by triggering the bug and printing the DNS response. The repository is structured with configuration files for the DNS server, example zone files, and a single exploit script. No weaponized payload is included; the exploit is intended for demonstration and educational purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.