← Vulnerability feed

Vulnerability record · CVE-1999-0532 · published 1 July 1997

CVE-1999-0532: DNS server permits unauthorized zone transfers

The record describes a DNS server that allows zone transfers to any requester. An unrestricted AXFR exposes the full contents of a DNS zone, including hostnames, subdomains and internal addressing, which aids reconnaissance and mapping of the target environment. The entry is very old and carries no vendor, product or version detail.

Not yet scored by NVD EPSS 69% · top 0.7%
—CVSS base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
3References
16 Jun 2026Last modified by NVD

Description

A DNS server allows zone transfers.

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: low.

medium priorityThe flaw leaks zone data useful for reconnaissance but grants no direct compromise, and the record lacks affected product detail and confirmed exploitation.

What it is

The record describes a DNS server that allows zone transfers to any requester. An unrestricted AXFR exposes the full contents of a DNS zone, including hostnames, subdomains and internal addressing, which aids reconnaissance and mapping of the target environment. The entry is very old and carries no vendor, product or version detail.

Impact

An attacker gains a complete listing of a DNS zone, revealing internal hostnames, subdomains and network structure that can be used to plan further attacks. No code execution or data modification is gained from the flaw itself.

Attack surface

Reached over the network via a standard DNS zone transfer request (AXFR) to the name server; no authentication is required and no user interaction is involved. The record does not specify which server software or configuration is affected.

Exploitation

Not listed in CISA KEV and no ransomware use is documented; EPSS is high at roughly 0.69 (99th percentile), but the references carry no exploit tags and the record provides no evidence of active exploitation.

What to do

  • Restrict zone transfers to explicitly authorized secondary name servers via ACLs or allow-transfer lists.
  • Disable zone transfers entirely on name servers that do not serve as a primary for secondaries.
  • Upgrade or replace end-of-life DNS server software that lacks modern access controls.
  • Segment and firewall DNS servers so port 53 is not reachable from untrusted networks.
  • Audit DNS configurations regularly to confirm zone transfer restrictions remain in place.

Detection

  • Monitor DNS logs for AXFR or IXFR requests from hosts that are not authorized secondaries.
  • Alert on zone transfer responses sent to external or unexpected source IP addresses.
  • Baseline normal zone transfer peers and flag any new or one-off requesters.
  • Correlate DNS zone transfer activity with subsequent scanning or enumeration from the same source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

References

Track CVE-1999-0532 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-1999-0532), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.