logo

Proof-of-concept code released for zero-click critical Windows vuln

ID: c5a11905-223b-55bc-88a5-96f48df37d52

STIX ID: report--c5a11905-223b-55bc-88a5-96f48df37d52

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-08-28

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

The report describes CVE-2024-38063, a critical (CVSS 9.8) Windows vulnerability allowing unauthenticated remote code execution via crafted IPv6 packets; a public PoC exploit by "Ynwarcs" has been released despite Microsoft issuing a patch on August 13. The PoC is described as flaky but reproducible under certain conditions, and the article warns administrators to apply the patch or mitigate by disabling IPv6.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.