Vulnerability record · CVE-1999-0532 · published 1 July 1997
CVE-1999-0532: DNS server permits unauthorized zone transfers
The record describes a DNS server that allows zone transfers to any requester. An unrestricted AXFR exposes the full contents of a DNS zone, including hostnames, subdomains and internal addressing, which aids reconnaissance and mapping of the target environment. The entry is very old and carries no vendor, product or version detail.
Description
A DNS server allows zone transfers.
Automated analysis
medium priorityThe flaw leaks zone data useful for reconnaissance but grants no direct compromise, and the record lacks affected product detail and confirmed exploitation.
What it is
The record describes a DNS server that allows zone transfers to any requester. An unrestricted AXFR exposes the full contents of a DNS zone, including hostnames, subdomains and internal addressing, which aids reconnaissance and mapping of the target environment. The entry is very old and carries no vendor, product or version detail.
Impact
An attacker gains a complete listing of a DNS zone, revealing internal hostnames, subdomains and network structure that can be used to plan further attacks. No code execution or data modification is gained from the flaw itself.
Attack surface
Reached over the network via a standard DNS zone transfer request (AXFR) to the name server; no authentication is required and no user interaction is involved. The record does not specify which server software or configuration is affected.
Exploitation
Not listed in CISA KEV and no ransomware use is documented; EPSS is high at roughly 0.69 (99th percentile), but the references carry no exploit tags and the record provides no evidence of active exploitation.
What to do
- Restrict zone transfers to explicitly authorized secondary name servers via ACLs or allow-transfer lists.
- Disable zone transfers entirely on name servers that do not serve as a primary for secondaries.
- Upgrade or replace end-of-life DNS server software that lacks modern access controls.
- Segment and firewall DNS servers so port 53 is not reachable from untrusted networks.
- Audit DNS configurations regularly to confirm zone transfer restrictions remain in place.
Detection
- Monitor DNS logs for AXFR or IXFR requests from hosts that are not authorized secondaries.
- Alert on zone transfer responses sent to external or unexpected source IP addresses.
- Baseline normal zone transfer peers and flag any new or one-off requesters.
- Correlate DNS zone transfer activity with subsequent scanning or enumeration from the same source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
References
Track CVE-1999-0532 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-1999-0532), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.