
THREAT LEVEL - HIGH
23-08-2024
New Critical Windows TCP/IP Remote Code Execution Vulnerability
Threat Level Description
IthacaLabs has maintained the Threat Level (High) adding a new observation:
An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.
Description
We have observed that a new critical vulnerability in Windows TCP/IP stack, has been identified.
An attacker, by exploiting this vulnerability, could achieve remote code execution and execute arbitrary code on affected systems.
The zero-click vulnerability tracked as CVE-2024-38063, which is rated 9.8 out of 10 on CVSS v3 score, is an integer underflow issue in the handling of IPv6 packets by the Windows TCP/IP stack.
When this underflow occurs the application falls into an indeterministic state, because of the lack of proper packet validation. These packets open the door for an attacker to send specially crafted network requests that exploit the system and compromise the system without any user interaction.
While Microsoft has not disclosed specific details on how the vulnerability is being exploited, it is widely believed that it is actively being targeted.
Affected Products
- Windows 10
- Windows 11
- Windows Server 2008
- Windows Server 2012
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
Recommendation(s)
You should proceed and apply all security patches and updates provided by the vendor. Furthermore you should disable IPv6 if updating is not possible and monitor for anomalous events.
You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.
References:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063



