#VU45817 Permissions, Privileges, and Access Controls in ISC BIND - CVE-2020-8624
Published: August 20, 2020
ISC BIND
ISC
Description
The vulnerability allows a remote user to perform unauthorized actions.
The vulnerability exists due to change 4885 in BIND inadvertently caused "update-policy" rules of type "subdomain" to be treated as if they were of type "zonesub", allowing updates to all parts of the zone along with the intended subdomain. A remote user with privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to update other contents of the zone.