Windows TCP/IP Zero-Click RCE via IPv6 (CVE-2024-38063)
Microsoft’s August 2024 Patch Tuesday (August 13) disclosed CVE-2024-38063, a critical vulnerability in the Windows TCP/IP stack. An attacker could achieve remote code execution on any vulnerable Windows system with IPv6 enabled simply by sending specially crafted IPv6 packets, with no user interaction required (zero-click).
The vulnerability affected all supported Windows versions. SANS Internet Storm Center and BleepingComputer provided coverage and mitigation guidance. Microsoft’s recommended mitigations included disabling IPv6 if not required, and promptly applying the patch.