CVE-2015-5477 is a reachable assertion vulnerability in ISC BIND's named DNS daemon. Incorrect handling of specially crafted TKEY queries triggers a REQUIRE assertion failure, terminating the daemon. Affected releases include BIND 9.1.0 through 9.8.x, 9.9.0 through 9.9.7-P1, and 9.10.0 through 9.10.2-P2. Both recursive and authoritative servers are vulnerable. Exploitation is remote and unauthenticated, and BIND access controls do not prevent it because the vulnerable code executes before those restrictions are checked.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit auxiliary module (modules/auxiliary/dos/dns/bind_tkey.rb) that exploits CVE-2015-5477, a denial-of-service vulnerability in ISC BIND9 DNS servers. The module constructs and sends a malformed DNS TKEY query packet to the target's UDP port 53. If the target is running a vulnerable version of BIND9, the server will crash with a REQUIRE assertion failure, resulting in a denial of service. The exploit allows optional spoofing of the source address. The code is written in Ruby and leverages Metasploit's auxiliary and UDP scanner modules. No hardcoded IPs or domains are present; the target is specified by the user. The repository is operational and suitable for use in testing or attacking vulnerable BIND9 instances.
This repository contains a proof-of-concept (PoC) exploit for CVE-2015-5477, a denial-of-service vulnerability in ISC BIND9's TKEY record processing. The repository consists of a single C source file (tkill.c) and a README.md. The exploit works by sending a specially crafted UDP packet (the 'dospacket') to the target's DNS service (port 53), which triggers an assertion failure and crashes the server. The code supports both IPv4 and IPv6, and can target multiple hosts or IPs specified on the command line. The exploit first sends a version query to check if the server is up, then sends the DoS packet, and waits to see if the server becomes unresponsive. The payload is hardcoded in the source and is not customizable. The exploit is cross-platform and can be compiled and run on Linux, macOS, and Windows (with appropriate toolchains). The README provides usage instructions and background on the vulnerability. The only notable endpoint in the code is a reference URL embedded in the DoS packet, which points to the exploit's GitHub repository.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A reachable assertion flaw in ISC BIND allowing remote denial of service through TKEY queries. CISA added it to KEV following exploitation attributed to Flax Typhoon.
A known exploited vulnerability added to CISA's catalog in connection with the reported Chinese government-linked intrusion activity. The content does not describe its technical mechanism or affected product.
A denial-of-service vulnerability in ISC BIND that can terminate the DNS server. It appears among the flaws successfully exploited by the reported hackers, although it is not itself described as an initial-access mechanism.
A critical vulnerability in BIND that the author states was discovered using AFL persistent mode fuzzing.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.