Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2024-38063 — PoC exploit and technical analysis for CVE-2024-38063 in the Windows IPv6 stack, built with Python and Scapy | Kitploit
Herramientas/GitHubGitHub/avidanmaatuk/cve-2024-38063
Vulnerability AnalysisExploitationNetwork SecurityLearning & EducationBinary ExploitationLabs & Practice
GitHubavidanmaatuk/cve-2024-38063

CVE-2024-38063

PoC exploit and technical analysis for CVE-2024-38063 in the Windows IPv6 stack, built with Python and Scapy

Ver Repositorio
117hace 22 díasAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

CVE-2024-38063 — Windows IPv6 Stack Vulnerability (Analysis & PoC)

Topic Focus Severity

Technical analysis and Proof-of-Concept (PoC) for CVE-2024-38063, a critical Remote Code Execution (RCE) vulnerability in the Windows IPv6 stack (tcpip.sys). Discovered by KunLun Lab, this issue is zero-click, meaning it can be triggered by specially crafted packets without user interaction.

Academic context: Final project for the “Foundations of Network Security” course.


Demo

Example BSOD


Table of Contents

  • Overview
  • Technical Summary
  • Repository Contents
  • Lab Setup
  • PoC Logic (High-Level)
  • Usage
  • Mitigation
  • What I Learned
  • Disclaimer

Overview

This repository contains:

  • a structured analysis of the vulnerability,
  • a PoC demonstration using Scapy,
  • and full course documentation and lab instructions.

Technical Summary

The core issue is an integer underflow in tcpip.sys during parsing of IPv6 Extension Headers within fragmented traffic.

  • Logic failure: header length validation fails during calculation.
  • Memory corruption: underflow leads to a buffer overflow and unsafe memory writes.
  • Impact: potential BSOD and RCE under specific conditions.

Repository Contents

  • CVE-2024-38063 Analysis.pdf — Slides covering background, root cause, and mitigations.
  • CVE-2024-38063.py — Scapy-based PoC script (demonstrates crash behavior).
  • WriteUP.pdf — Full write-up, lab requirements, and execution notes.

Lab Setup

To reproduce the environment in a controlled, educational lab:

  • Victim: Windows 10/11 prior to Aug 2024 patch / 24H2, IPv6 enabled.
  • Attacker: Linux VM with Python 3, Scapy.
  • Network: IPv6 connectivity between both machines on the same network segment.

PoC Logic (High-Level)

The PoC crafts a sequence of packets to trigger the underflow:

  1. Destination Options with an unrecognized option type to push error-handling paths.
  2. Fragment 1 to start fragmentation and provide payload.
  3. Fragment 2 to terminate the sequence.

The script repeats these batches while varying the Hop Limit to increase the probability of encountering the vulnerable parsing path.


Usage

  1. Identify the target IPv6 address.
  2. Update ip_addr and iface in CVE-2024-38063.py.
  3. Run the script from the attacker machine:
pip install scapy
pip install getmac
python3 CVE-2024-38063.py

If the target is vulnerable, a BSOD typically occurs within 30–60 seconds as the kernel processes malformed headers.


Mitigation

  • Apply security updates: Microsoft patch (Aug 13, 2024).
  • Disable IPv6 where patching is not possible.
  • Firewall filtering: block fragmented IPv6 packets at the perimeter.

What I Learned

  • IPv6 Header Architecture: Deepened my understanding of next-header chaining (Hop-by-Hop, Destination Options, and Fragmentation), and how nested header complexity broadens the network attack surface.
  • Kernel-Level Packet Ingestion (tcpip.sys): Observed Ring 0 packet processing firsthand. Because fragmentation reassembly and parsing occur deep inside the network driver before reaching user-mode sockets, flaws at this layer bypass host-level software controls and enable zero-click exploitation.
  • Root-Cause Vulnerability Mechanics: Analyzed how an integer underflow in header-length calculation corrupts pointer offsets, translating an arithmetic flaw into out-of-bounds kernel memory writes and system panics (BSOD).
  • Custom Packet Crafting with Scapy: Gained hands-on experience constructing non-RFC-compliant packets, injecting malformed Destination Option TLVs (Type-Length-Value), and sequencing fragments to force edge-case error handling in the target kernel.

Disclaimer

This project is for educational and research purposes only. Unauthorized testing or access to systems you do not own or have explicit permission to assess is illegal. The authors assume no responsibility for misuse.

Descargar herramienta