CVE-2008-1447
MEDIUM 6.8EPSS 95.2%
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."
- CVSS v3.1
- 6.8 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 95.18% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2008-07-08
- Updated
- 2024-08-07
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/6130
- https://www.exploit-db.com/exploits/6123
- https://www.exploit-db.com/exploits/6122