mitigation script by disabling ipv6 of all interfaces

Windows TCP/IP Remote Code Execution Vulnerability

Published 13 Aug 2024Updated 17 Jun 202667 sources
CVSS 9.8 ✓ VERIFIED REFERENCE

What happened

Windows TCP/IP Remote Code Execution Vulnerability

Affected versions

Windows 10 Version 1809: 10.0.17763.0 through before 10.0.17763.6293 (custom); 10.0.20348.0 through before 10.0.20348.2700 (custom); 10.0.0 through before 10.0.22000.3197 (custom); 10.0.19043.0 through before 10.0.19044.4780 (custom); 10.0.22621.0 through before 10.0.22621.4037 (custom); 10.0.19045.0 through before 10.0.19045.4780 (custom); 10.0.22631.0 through before 10.0.22631.4037 (custom); 10.0.25398.0 through before 10.0.25398.1085 (custom); 10.0.10240.0 through before 10.0.10240.20751 (custom); 10.0.14393.0 through before 10.0.14393.7259 (custom); 6.0.6003.0 through before 6.0.6003.22825 (custom); 6.1.7601.0 through before 6.1.7601.27277 (custom); 6.2.9200.0 through before 6.2.9200.25031 (custom); 6.3.9600.0 through before 6.3.9600.22134 (custom); 10.0.26100.0 through before 10.0.26100.1457 (custom) Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
PoC-in-GitHub · diegoalbuquerque/CVE-2024-38063mitigation script by disabling ipv6 of all interfaces★ 13diegoalbuquerque2024-08-15VerifiedPoC-in-GitHub · Sachinart/CVE-2024-38063-pocNote: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.★ 86Sachinart2024-08-17CandidatePoC-in-GitHub · dweger-scripts/CVE-2024-38063-Remediation★ 0dweger-scripts2024-08-19CandidatePoC-in-GitHub · almogopp/Disable-IPv6-CVE-2024-38063-FixA PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the registry to reduce the risk of exploitation without needing the immediate installation of the official Microsoft KB update. Intended as a temporary fix★ 0almogopp2024-08-20CandidatePoC-in-GitHub · Th3Tr1ckst3r/CVE-2024-38063CVE-2024-38063 research so you don't have to.★ 2Th3Tr1ckst3r2024-08-23CandidatePoC-in-GitHub · ynwarcs/CVE-2024-38063poc for CVE-2024-38063 (RCE in tcpip.sys)★ 692ynwarcs2024-08-24CandidatePoC-in-GitHub · patchpoint/CVE-2024-38063★ 20patchpoint2024-08-27CandidatePoC-in-GitHub · PumpkinBridge/Windows-CVE-2024-38063Windows TCP/IP IPv6(CVE-2024-38063)★ 4PumpkinBridge2024-08-28CandidatePoC-in-GitHub · zenzue/CVE-2024-38063-POCpotential memory corruption vulnerabilities in IPv6 networks.★ 7zenzue2024-08-28CandidatePoC-in-GitHub · AdminPentester/CVE-2024-38063-Remotely Exploiting The Kernel Via IPv6★ 2AdminPentester2024-08-28CandidatePoC-in-GitHub · ThemeHackers/CVE-2024-38063CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)★ 44ThemeHackers2024-08-31CandidatePoC-in-GitHub · KernelKraze/CVE-2024-38063_PoCThis is a C language program designed to test the Windows TCP/IP Remote Code Execution Vulnerability (CVE-2024-38063). It sends specially crafted IPv6 packets with embedded shellcode to exploit the vulnerability.★ 9KernelKraze2024-09-01CandidatePoC-in-GitHub · ps-interactive/cve-2024-38063★ 0ps-interactive2024-09-02CandidatePoC-in-GitHub · brownpanda29/Cve-2024-38063★ 1brownpanda292024-09-03CandidatePoC-in-GitHub · FrancescoDiSalesGithub/quick-fix-cve-2024-38063quick powershell script to fix cve-2024-38063★ 0FrancescoDiSalesGithub2024-09-07CandidatePoC-in-GitHub · Faizan-Khanx/CVE-2024-38063CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6★ 1Faizan-Khanx2024-09-10CandidatePoC-in-GitHub · ArenaldyP/CVE-2024-38063-MediumKode Eksploitasi CVE-2024-38063★ 0ArenaldyP2024-09-21CandidatePoC-in-GitHub · becrevex/CVE-2024-38063Performs an IPv6 vulnerability scan and packet flood attack on specified targets. The script simulates a SYN flood and ICMP flood attack and optionally sends exploit packets.★ 1becrevex2024-10-08CandidatePoC-in-GitHub · idkwastaken/CVE-2024-38063★ 0idkwastaken2024-10-14CandidatePoC-in-GitHub · thanawee321/CVE-2024-38063Vulnerability CVE-2024-38063★ 3thanawee3212024-10-15CandidatePoC-in-GitHub · AliHj98/cve-2024-38063-Anonyvader★ 1AliHj982024-11-07CandidatePoC-in-GitHub · Dragkob/CVE-2024-38063PoC for Windows' IPv6 CVE-2024-38063★ 3Dragkob2024-11-16CandidatePoC-in-GitHub · fredagsguf/Windows-CVE-2024-38063★ 0fredagsguf2024-12-06CandidatePoC-in-GitHub · jip-0-0-0-0-0/CVE-2024-38063-scannerA Python tool leveraging Shodan and Scapy to identify and exploit Windows systems vulnerable to CVE-2024-38063, enabling targeted Denial of Service attacks★ 1jip-0-0-0-0-02025-01-16CandidatePoC-in-GitHub · Skac44/CVE-2024-38063★ 0Skac442025-07-23CandidatePoC-in-GitHub · thealice01/CVE-2024-38063SSP H3★ 0thealice012026-01-20CandidatePoC-in-GitHub · AvidanMaatuk/CVE-2024-38063Final Project in Fundamental network security,POC CVE-202438063★ 1AvidanMaatuk2026-01-21CandidatePoC-in-GitHub · arrhenius975/CVE-2024-38063-Exploit-Refactoring★ 0arrhenius9752026-03-04CandidatePoC-in-GitHub · SALMA-ESSAOUD/CVE-CVSS--CVE-2024-38063-IPv6-TCP-IP-Remote-Code-Execution-Analysis★ 0SALMA-ESSAOUD2026-03-21CandidatePoC-in-GitHub · RohitMalik7/cve-2024-38063-detection-mitigation-systemEnd-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack simulation.★ 0RohitMalik72026-04-24CandidatePoC-in-GitHub · Mayank637-pixel/CVE-2024-38063★ 0Mayank637-pixel2026-09-06CandidatehibaNITT/CVE-2024-38063Exploit for Integer Underflow (Wrap or Wraparound) in MicrosofthibaNITT2026-09-06T12:53:36VerifiedSploitusExploit for Integer Underflow (Wrap or Wraparound) in MicrosofthibaNITT2026-09-06T12:53:36Verified