logo

Researchers Follow the Breadcrumbs: The Latest Vulnerabilities in Windows’ Network Stack

ID: 9e02ba87-e1ef-5555-b226-e828e186f79e

STIX ID: report--9e02ba87-e1ef-5555-b226-e828e186f79e

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2021-02-09

Date Updated: 2026-04-28

Author: Steve Povolny

...
...

This report summarizes McAfee's analysis of three critical vulnerabilities in Windows' tcpip.sys affecting IPv4/IPv6 packet reassembly: an internet-routable IPv6 fragmentation NULL-pointer crash causing persistent DoS (CVE-2021-24086), an IPv6 dangling pointer that can produce BSOD and has limited RCE potential (CVE-2021-24094), and an IPv4 IP Options type confusion enabling OOB read/write with exploitation complexity but rated "exploitation more likely" (CVE-2021-24074). The authors highlight detection signs, exploitation challenges, potential for wormability, and recommend prompt patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.