Severe 0-Click Remote Code Execution Vulnerability in Windows TCP/IP Stack Affects Every System

Microsoft has issued an urgent security patch to tackle a severe remote code execution flaw in the Windows TCP/IP stack. This vulnerability, designated as CVE-2024-38063, impacts all current versions of Windows and Windows Server, including Server Core setups.

CVE-2024-38063 is categorized with the highest severity level of Critical and has a CVSSv3 score of 9.8. Here are the critical points:

  • An attacker can exploit this flaw remotely by sending maliciously crafted IPv6 packets to a vulnerable host.
  • The exploit requires no user interaction, classifying it as a “0-click” vulnerability.
  • Only IPv6 packets can be used to exploit this issue.
  • Microsoft has classified this vulnerability as “Exploitation More Likely.”

If successfully exploited, CVE-2024-38063 could allow an attacker to run arbitrary code on the affected system with SYSTEM privileges, granting complete control over the compromised machine.

“An unauthenticated attacker could repeatedly send specially crafted IPv6 packets to a Windows machine, potentially leading to remote code execution,” Microsoft explained.

The flaw affects all supported editions of:

  • Windows
  • Windows Server (including Server Core).

Microsoft has released updates to address this issue for all affected Windows and Windows Server versions. It is strongly recommended that organizations apply these updates promptly.

To further mitigate the risk, Microsoft advises disabling IPv6 if it is not necessary for your environment, as this vulnerability is only exploitable via IPv6 packets.

Additionally, Microsoft has addressed six active zero-day vulnerabilities that were being exploited in the wild.

Recommended actions include:

  • Immediately apply the latest Microsoft security updates.
  • Focus on patching systems exposed to the internet.
  • Disable IPv6 if it is not used in your environment.
  • Keep an eye out for unusual network activity, especially involving IPv6 traffic.
  • Implement network segmentation to restrict potential lateral movement if a system is compromised.

Due to the critical nature of this vulnerability and its potential for widespread damage, addressing CVE-2024-38063 should be a top priority.

For users of the new Copilot+ devices, which come pre-installed with Windows 11, version 24H2, it is essential to stay informed about any vulnerabilities affecting their devices and ensure updates are applied if automatic updates are not enabled. Windows 11, version 24H2 is expected to become widely available later this year, according to Microsoft.

More Articles & Posts