logo

Microsoft, Late to the Game on Dangerous DNSSEC Zero-Day Flaw

ID: 5b37e2ee-44e4-5907-a59c-8fd578cd2780

STIX ID: report--5b37e2ee-44e4-5907-a59c-8fd578cd2780

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-06-13

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

The article reports on two serious DNSSEC resource-exhaustion vulnerabilities (CVE-2023-50868 and CVE-2023-50387/KeyTrap) that allow attackers to craft DNS packets to exhaust resolver CPU and cause DoS; multiple vendors released patches earlier, but Microsoft delayed fixing CVE-2023-50868 making it a zero-day for Microsoft until recently. The piece highlights the cross-industry coordination to mitigate protocol-level flaws, the implementation complexity of fixes, and the risk that such flaws pose to DNS availability and cache-poisoning windows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.