CTD-000091

DNS zone allowing unsecure update

Critical
Active Directory DNS
Credential Access Defense Evasion
v24

Signature Identity

CTD-000091
Threat ID
24
Version
IOE
Indicator Type

Threat Description

Unsecure dynamic updates allow a threat actor to update a DNS record without authentication. Threat actor can replace an existing DNS record and redirect people to another server. If enabling Dynamic updates is required for a company, it is highly recommended to use Secure only dynamic updates option.

This is because a DNS update source is considered as trusted only if:

  1. The DNS update source was authenticated against Active Directory
  2. The DNS update source has the permission to update the DNS record

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To disable unsecure dynamic updates:

  1. Click Start.
  2. Point to Administrative Tools.
  3. Click DNS.
  4. Under DNS:
    1. Double-click the applicable DNS server.
    2. Double-click Forward Lookup Zones or Reverse Lookup Zones.
    3. Right-click the applicable zone.
  5. Click Properties.
  6. On the General tab, verify that the zone type is Active Directory-integrated.
  7. In the Dynamic updates box, click Secure only or None.
  8. Click OK.

Frequently Asked Questions

What does DNS zone allowing unsecure update mean?

A DNS zone configured for dynamic updates from any source without authentication allows an attacker to modify existing DNS records, including domain names and IP addresses, without valid credentials. This enables attackers to make unauthorized changes to DNS records.

This vulnerability is rated critical because it enables attackers to exploit the lack of authentication for dynamic updates, which can be used to redirect users to malicious servers via DNS spoofing or cache poisoning attacks. This access matters because it allows attackers to compromise user trust and facilitate phishing, malware distribution, or other types of attacks.

Attackers can modify existing DNS records and redirect users to malicious servers by exploiting the lack of authentication for dynamic updates. This can be used for phishing, malware distribution, or other types of attacks that rely on compromising user trust. The capability gained by attackers matters because it enables them to persist in the environment and evade detection.

Cayosoft Guardian monitors DNS zone configurations and identifies those that allow unsecured dynamic updates, providing administrators with visibility into potential security risks and enabling them to take corrective action. This detection supports investigation by providing clear evidence of the vulnerability.

Cayosoft Guardian alerts administrators to the issue and provides guidance on how to remediate it, including configuring secure dynamic updates or disabling dynamic updates altogether, depending on the organization's needs. This support helps teams respond by providing a clear plan for remediating the vulnerability.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory DNS
Themes
Infrastructure
Attack Tactics
Credential Access Defense Evasion
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical