PT-2024-5563 · Microsoft · Windows
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows (affected versions not specified)
Description
A remote code execution issue exists in the Microsoft Windows TCP/IP implementation. The flaw is caused by an integer underflow in the kernel driver responsible for handling IPv6 packets. A remote attacker can exploit this by sending specially crafted network packets via the IPv6 protocol, allowing for arbitrary code execution without any user interaction. This issue has been exploited in the wild, notably in a campaign targeting an Israeli retail company to steal a credit card database containing 1.7 million records.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation measure, consider disabling IPv6 to minimize the risk of exploitation.
Exploit
DoS
RCE
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows