logo

Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch now

ID: 8247e94a-1608-5ac2-8b16-cad1b1309831

STIX ID: report--8247e94a-1608-5ac2-8b16-cad1b1309831

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-08-14

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft disclosed CVE-2024-38063, a critical integer-underflow vulnerability in the Windows TCP/IP IPv6 stack that allows unauthenticated remote code execution via specially crafted IPv6 packets; the flaw is described as wormable and tagged by Microsoft as “exploitation more likely,” so users are urged to apply security updates immediately or temporarily disable IPv6 despite potential side effects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.