Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch now
https://www.bleepingcomputer.com/news/microsoft/zero-click-windows-tcp-ip-rce-impacts-all-systems-with-ipv6-enabled-patch-now/ ^ | 08-14-2024 | https://www.bleepingcomputer.com (& many others)

Posted on 08/21/2024 1:50:54 AM PDT by Drago

Microsoft warned customers this Tuesday to patch a critical TCP/IP remote code execution (RCE) vulnerability with an increased likelihood of exploitation that impacts all Windows systems using IPv6, which is enabled by default.

Found by Kunlun Lab's XiaoWei and tracked as CVE-2024-38063, this security bug is caused by an Integer Underflow weakness, which attackers could exploit to trigger buffer overflows that can be used to execute arbitrary code on vulnerable Windows 10, Windows 11, and Windows Server systems.

(Excerpt) Read more at bleepingcomputer.com ...


TOPICS:
KEYWORDS: microsoft; vulnerability; windows; windowspinglist; zeroday
Navigation: use the links below to view more comments.
first 1-2021-22 next last
Several "zero day"/"no user click required" vulnerabilities patched in the last couple weeks...if on Windows patch now.
1 posted on 08/21/2024 1:50:54 AM PDT by Drago
[ Post Reply | Private Reply | View Replies]

To: All; Drago

A good “explainer” video on the topic:

https://youtu.be/qhQRSUYnVG4?si=xwMAWHP2Jv-mBm-V

Other recent Windows patches:

https://krebsonsecurity.com/2024/08/six-0-days-lead-microsofts-august-2024-patch-push/


2 posted on 08/21/2024 1:52:30 AM PDT by Drago
[ Post Reply | Private Reply | To 1 | View Replies]

To: Drago

>>Several “zero day”/”no user click required” vulnerabilities patched in the last couple weeks...if on Windows patch now.

Linux: the last Windows security patch you’ll ever need.


3 posted on 08/21/2024 3:24:53 AM PDT by vikingd00d (chown -R us ~you/base)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

ping to you


4 posted on 08/21/2024 3:48:14 AM PDT by kiryandil (FR Democrat Party operatives! Rally in defense of your Colombian cartel stooge Merchan!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: vikingd00d

I’ve installed Linux Mint Cinnamon/Virginia on TWO former Windoze machines (IBM Lenovo Laptop and an INTEL NUC mini) and couldn’t be happier.

Why the trouble?

That crash that took out Win 10/11 machines last month? Also took out Win 7+ on the NUC; I’d already had Linux running on the laptop for about a year just to figure it out.

I’m not missing anything.


5 posted on 08/21/2024 3:58:47 AM PDT by normbal (normbal. somewhere in socialist occupied America ‘tween MD and TN)
[ Post Reply | Private Reply | To 3 | View Replies]

To: normbal

“I’m not missing anything.”

Yep, I’m nine years in on Linux now. Should have done it even sooner.


6 posted on 08/21/2024 4:07:24 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 5 | View Replies]

To: normbal

That’s okay. Your particular distro was one of the first compromises in this years Pwn2Own at BlackHat. Windows 11? Fifth. So you can continue living in your belief that Linux is natively secure. If you can’t work in Linux without the CLI, you’re relying on a volunteer community to keep you safe.


7 posted on 08/21/2024 4:43:48 AM PDT by rarestia (“A nation which can prefer disgrace to danger is prepared for a master, and deserves one.” -Hamilton)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Drago; dayglored; ShadowAce; Swordmaker

Ping!..................


8 posted on 08/21/2024 5:01:42 AM PDT by Red Badger (Homeless veterans camp in the streets while illegals are put up in 5 Star hotels....................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kiryandil; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; ..
Windows 10/11 Patch Now! ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to kiryandil for the ping!

9 posted on 08/21/2024 5:58:11 AM PDT by dayglored (“Courtesy is owed. Respect is earned. Love is given.” - Kinky Friedman 1944-2024)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored

Unless you are actually using IPv6... it should be shut off.

I was doing this with my clients before this happened. Why leave something set and running if you don’t need it and aren’t using it?

I’ve worked with hundreds of clients and only ONE was actually using IPv6. Then again, they were using ZTN as well, so there’s that.


10 posted on 08/21/2024 6:39:50 AM PDT by Dead Corpse (A Psalm in napalm...)
[ Post Reply | Private Reply | To 9 | View Replies]

To: vikingd00d
Re: "Linux: the last Windows security patch you'll ever need."

Good laugh line.

However, what happens when Linux hits a 72% market share - like Windows today - and every hacker in the world starts attacking Linux?

Where is the central certified Linux authority that takes responsibility for fixing a Linux vulnerability?

How would you know an alleged Linux patch is not new demon software designed by brilliant hackers?

11 posted on 08/21/2024 7:47:15 AM PDT by zeestephen (Trump "Lost" By 43,000 Votes - Spread Across Three States - GA, WI, AZ)
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored

Thanks for the ‘heads up’ as I refuse to trust Doze Automatic Updates (after they ruined drives, requiring re-installations). I’d be on Linux but this awesome Dell refurb from Amazon ($260 for a $1,200 computer) came with Win 10 - which has been good so far. Stay safe!


12 posted on 08/21/2024 7:48:06 AM PDT by MikelTackNailer (We can never stop failing for the minute we do, we fail.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Dead Corpse

Ok...how do I shut it off?


13 posted on 08/21/2024 8:04:06 AM PDT by goodnesswins (DEI....Divide, Enslave, Indoctrinate.....OR ......Didn't Earn It)
[ Post Reply | Private Reply | To 10 | View Replies]

To: vikingd00d

“Linux: the last Windows security patch you’ll ever need.”

That’s true.


14 posted on 08/21/2024 8:14:35 AM PDT by Dalberg-Acton
[ Post Reply | Private Reply | To 3 | View Replies]

To: Drago

I thought this thread would be more focused on the topic instead of Linux.


15 posted on 08/21/2024 8:28:16 AM PDT by ansel12 ((NATO warrior under Reagan, and RA under Nixon, bemoaning the pro-Russians from Vietnam to Ukraine.))
[ Post Reply | Private Reply | To 1 | View Replies]

To: goodnesswins

Start menu -> Settings -> Network and Internet -> Change Adapter Options

Right-click on which ever adapter you want to adjust.
Properties
“This connection uses the following items:”
Scroll down to Internet Protocol Version 6 (TCP/IPv6)
Uncheck the box and hit Ok.


16 posted on 08/21/2024 9:04:59 AM PDT by Dead Corpse (A Psalm in napalm...)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Dalberg-Acton

Not quite...

https://www.zdnet.com/article/patch-now-this-serious-linux-vulnerability-affects-nearly-all-distributions/

https://phoenixnap.com/kb/linux-security

https://www.zdnet.com/article/linux-network-security-holes-found-fixed/


17 posted on 08/21/2024 9:53:45 AM PDT by Dead Corpse (A Psalm in napalm...)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Dead Corpse

Thank YOU


18 posted on 08/21/2024 11:24:08 AM PDT by goodnesswins (DEI....Divide, Enslave, Indoctrinate.....OR ......Didn't Earn It)
[ Post Reply | Private Reply | To 16 | View Replies]

To: goodnesswins

If it helps, glad to be of service. :-)


19 posted on 08/21/2024 11:26:31 AM PDT by Dead Corpse (A Psalm in napalm...)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Dead Corpse

Yep. Just like Apple products “never had to be patched” ™
that didn’t age well.


20 posted on 08/21/2024 12:18:18 PM PDT by AbolishCSEU (Amount of "child" support paid is inversely proportionate to mother's actual parenting of children)
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-22 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson