Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch now
ID: 8247e94a-1608-5ac2-8b16-cad1b1309831
STIX ID: report--8247e94a-1608-5ac2-8b16-cad1b1309831
Feed Name: Bleeping Computer
Threat Score
Microsoft disclosed CVE-2024-38063, a critical integer-underflow vulnerability in the Windows TCP/IP IPv6 stack that allows unauthenticated remote code execution via specially crafted IPv6 packets; the flaw is described as wormable and tagged by Microsoft as “exploitation more likely,” so users are urged to apply security updates immediately or temporarily disable IPv6 despite potential side effects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
