CVE-2017-3141 describes a privilege escalation vulnerability in the BIND installer for Windows, affecting numerous versions of BIND 9. The flaw stems from the use of an unquoted service path, which a local user can exploit if file system permissions permit. This high-severity vulnerability (CVSS 7.8) allows for complete compromise of confidentiality, integrity, and availability on the affected system. While not listed in CISA's KEV catalog, public exploit code exists on ExploitDB, and it has garnered community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.2.6, <= 9.2.9CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.3.2, <= 9.3.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.4.0, <= 9.8.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.9.0, <= 9.9.10CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.10.0, <= 9.10.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.