← Vulnerability feed

Vulnerability record · CVE-2008-1447 · published 8 July 2008

CVE-2008-1447: DNS resolvers allow cache poisoning via insufficient transaction ID and source port entropy

Isc · Bind

The DNS protocol as implemented in BIND 8 and 9 (before 9.5.0-P1, 9.4.2-P1, 9.3.5-P1), Microsoft DNS on Windows 2000 SP4, XP SP2/SP3 and Server 2003 SP1/SP2, and other implementations uses insufficient randomness in DNS transaction IDs and source ports. A remote attacker can use a birthday attack with in-bailiwick referrals to spoof DNS responses and poison the cache of a recursive resolver. This is the well-known Kaminsky bug, and successful poisoning lets an attacker redirect name resolution for many users.

6.8 CVSS 3.1 Medium EPSS 95% · top 0.1% CWE-331 · CWE-331
6.8CVSS 3.1 base score, v2 5.0
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
392References
16 Jun 2026Last modified by NVD

Description

The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw enables remote cache poisoning of recursive resolvers with no authentication or user interaction, and EPSS is extremely high, though the CVSS score is medium and KEV listing is absent.

What it is

The DNS protocol as implemented in BIND 8 and 9 (before 9.5.0-P1, 9.4.2-P1, 9.3.5-P1), Microsoft DNS on Windows 2000 SP4, XP SP2/SP3 and Server 2003 SP1/SP2, and other implementations uses insufficient randomness in DNS transaction IDs and source ports. A remote attacker can use a birthday attack with in-bailiwick referrals to spoof DNS responses and poison the cache of a recursive resolver. This is the well-known Kaminsky bug, and successful poisoning lets an attacker redirect name resolution for many users.

Impact

An attacker who poisons a recursive resolver's cache can return forged answers for arbitrary domains, redirecting victims to attacker-controlled hosts for further credential theft, malware delivery or traffic interception. The CVSS vector shows high integrity impact with no confidentiality or availability impact.

Attack surface

Reachable over the network by sending spoofed DNS responses to a recursive resolver; no authentication and no user interaction are required. The attacker must race the legitimate response and predict transaction IDs and source ports.

Exploitation

The record is not listed in CISA KEV and has no exploit-tagged references, but EPSS is very high (0.95182 probability, 99.861 percentile), indicating strong likelihood of exploitation activity. The references are advisories and technical descriptions rather than exploit code.

What to do

  • Patch BIND to 9.5.0-P1, 9.4.2-P1 or 9.3.5-P1, and apply the corresponding Microsoft DNS and other vendor updates for the affected Windows versions.
  • Where patching is not immediately possible, restrict recursive resolution to trusted clients and disable open recursion.
  • Enable source port randomization and, where supported, DNSSEC validation to detect forged answers.
  • Segment or firewall recursive resolvers so they are not reachable from untrusted networks.
  • Monitor vendor advisories for the affected platforms and apply follow-up fixes.

Detection

  • Monitor resolver logs for a high volume of unexpected or mismatched DNS responses and cache changes for domains the resolver did not query.
  • Alert on sudden changes in resolution results for high-value domains, such as internal or authentication-related names.
  • Use DNSSEC validation failures or anomalies as an indicator of forged responses.
  • Baseline normal query and response patterns per resolver and flag deviations consistent with spoofing attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-009.txt.asc Third Party AdvisoryVendor Advisory
http://blog.invisibledenizen.org/2008/07/kaminskys-dns-issue-accidentally-leaked.html Technical Description
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494401 Third Party Advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01523520 Broken Link
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01662368 Broken Link
http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html Mailing ListThird Party Advisory
http://lists.apple.com/archives/security-announce//2008/Sep/msg00003.html Mailing ListThird Party Advisory
http://lists.apple.com/archives/security-announce//2008/Sep/msg00004.html Mailing ListThird Party Advisory
http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html Mailing ListThird Party Advisory
http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00003.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html Third Party Advisory
http://marc.info/?l=bugtraq&m=121630706004256&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=121866517322103&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=123324863916385&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141879471518471&w=2 Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2008-0533.html Third Party Advisory
http://secunia.com/advisories/30925 Third Party Advisory
http://secunia.com/advisories/30973 Third Party Advisory
http://secunia.com/advisories/30977 Third Party Advisory
http://secunia.com/advisories/30979 Third Party Advisory
http://secunia.com/advisories/30980 Third Party Advisory
http://secunia.com/advisories/30988 Third Party AdvisoryVendor Advisory
http://secunia.com/advisories/30989 Vendor Advisory
http://secunia.com/advisories/30998 Third Party Advisory
http://secunia.com/advisories/31011 Third Party Advisory
http://secunia.com/advisories/31012 Third Party Advisory
http://secunia.com/advisories/31014 Third Party Advisory
http://secunia.com/advisories/31019 Third Party Advisory
http://secunia.com/advisories/31022 Third Party Advisory
http://secunia.com/advisories/31030 Third Party Advisory
http://secunia.com/advisories/31031 Third Party Advisory
http://secunia.com/advisories/31033 Vendor Advisory
http://secunia.com/advisories/31052 Vendor Advisory
http://secunia.com/advisories/31065 Third Party Advisory
http://secunia.com/advisories/31072 Third Party Advisory
http://secunia.com/advisories/31093 Third Party Advisory
http://secunia.com/advisories/31094 Vendor Advisory
http://secunia.com/advisories/31137 Vendor Advisory
http://secunia.com/advisories/31143 Third Party Advisory

Track CVE-2008-1447 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2008-1447), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.