ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

New Windows IPv6 Zero-Click Vulnerability

criticalVulnerabilityimportance 55
Full article111 words · extracted from schneier.com · click to collapse

The press is reporting a critical Windows vulnerability affecting IPv6.

As Microsoft explained in its Tuesday advisory, unauthenticated attackers can exploit the flaw remotely in low-complexity attacks by repeatedly sending IPv6 packets that include specially crafted packets.

Microsoft also shared its exploitability assessment for this critical vulnerability, tagging it with an “exploitation more likely” label, which means that threat actors could create exploit code to “consistently exploit the flaw in attacks.”

Details are being withheld at the moment. Microsoft strongly recommends patching now.

Tags: Microsoft, patching, vulnerabilities, Windows

Posted on August 16, 2024 at 7:07 AM13 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2024/08/new-windows-ipv6-zero-click-vulnerability.html