Microsoft, Late to the Game on Dangerous DNSSEC Zero-Day Flaw
ID: 5b37e2ee-44e4-5907-a59c-8fd578cd2780
STIX ID: report--5b37e2ee-44e4-5907-a59c-8fd578cd2780
Feed Name: Dark Reading
The article reports on two serious DNSSEC resource-exhaustion vulnerabilities (CVE-2023-50868 and CVE-2023-50387/KeyTrap) that allow attackers to craft DNS packets to exhaust resolver CPU and cause DoS; multiple vendors released patches earlier, but Microsoft delayed fixing CVE-2023-50868 making it a zero-day for Microsoft until recently. The piece highlights the cross-industry coordination to mitigate protocol-level flaws, the implementation complexity of fixes, and the risk that such flaws pose to DNS availability and cache-poisoning windows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
