On August 13, 2024, Microsoft
disclosed a critical vulnerability, which has been assigned a
CVSS score of 9.8, marking it as a critical threat.
CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE). This vulnerability affects the TCP/IP protocol, a fundamental communication protocol used for connecting devices on the Internet. The vulnerability is due to improper handling of IPv6 network packets by Windows, which can be exploited by an attacker to execute arbitrary code on a vulnerable system.
The vulnerability targets systems with
IPv6 enabled, which is the default configuration for many affected platforms. Impacted versions include a broad range of
Windows operating systems, from
Windows 10 and
Windows 11 to
Windows Server versions 2008 through 2022.
Given the severity of this flaw, organizations are urged to
immediately update their systems to mitigate the risk of remote code execution (RCE) and prevent potential exploitation.
Passeca's experts have already discovered PoC exploits in public.