Windows TCP/IP Remote Code Execution Vulnerability

  • FEBRUARY 26TH, 2024
  • 1min read
Windows TCP/IP Remote Code Execution Vulnerability

Introduction

A vulnerability, CVE-2024-38063 MSRC of high severity, which impacts all Windows systems using IPv6 has been identified. It allows unauthenticated attackers to repeatedly send IPv6 packets, including specially crafted ones, to a Windows machine, enabling remote code execution. This vulnerability is self-replicating and does not require attacker privileges or user login.

Steps to Take

  • Install Updates: Apply the latest Microsoft patch.
  • Disable IPv6: Follow the steps below to mitigate the risk.

How to Disable IPv6

  1. Go to the Control Panel and click Network and Internet.
  2. Click Network and Sharing Centre, then View network status and tasks.
  3. Click your network adapter and select Properties.
  4. Uncheck Internet Protocol Version 6 (TCP/IPv6) and click OK.

Note: A restart may be required for updates to take effect.

Never miss a CIL Security Advisory

Stay informed with the latest security updates and insights from CIL.

Windows TCP/IP Remote Code Execution Vulnerability

Contact Us

Message Sent!

Thank you for reaching out. We have received your message and will get back to you shortly.

Check your email for a confirmation from us.

Start a project

Project Request Submitted!

Thank you for your interest. Our team will review your project details and reach out to you soon.

Check your email for a confirmation from us.