Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2024-38063 — PoC exploit and technical analysis for CVE-2024-38063 in the Windows IPv6 stack, built with Python and Scapy | Kitploit
Outils/GitHubGitHub/avidanmaatuk/cve-2024-38063
Vulnerability AnalysisExploitationNetwork SecurityLearning & EducationBinary ExploitationLabs & Practice
GitHubavidanmaatuk/cve-2024-38063

CVE-2024-38063

PoC exploit and technical analysis for CVE-2024-38063 in the Windows IPv6 stack, built with Python and Scapy

Voir le dépôt
117il y a 21 joursPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

CVE-2024-38063 — Windows IPv6 Stack Vulnerability (Analysis & PoC)

Topic Focus Severity

Technical analysis and Proof-of-Concept (PoC) for CVE-2024-38063, a critical Remote Code Execution (RCE) vulnerability in the Windows IPv6 stack (tcpip.sys). Discovered by KunLun Lab, this issue is zero-click, meaning it can be triggered by specially crafted packets without user interaction.

Academic context: Final project for the “Foundations of Network Security” course.


Demo

Example BSOD


Table of Contents

  • Overview
  • Technical Summary
  • Repository Contents
  • Lab Setup
  • PoC Logic (High-Level)
  • Usage
  • Mitigation
  • What I Learned
  • Disclaimer

Overview

This repository contains:

  • a structured analysis of the vulnerability,
  • a PoC demonstration using Scapy,
  • and full course documentation and lab instructions.

Technical Summary

The core issue is an integer underflow in tcpip.sys during parsing of IPv6 Extension Headers within fragmented traffic.

  • Logic failure: header length validation fails during calculation.
  • Memory corruption: underflow leads to a buffer overflow and unsafe memory writes.
  • Impact: potential BSOD and RCE under specific conditions.

Repository Contents

  • CVE-2024-38063 Analysis.pdf — Slides covering background, root cause, and mitigations.
  • CVE-2024-38063.py — Scapy-based PoC script (demonstrates crash behavior).
  • WriteUP.pdf — Full write-up, lab requirements, and execution notes.

Lab Setup

To reproduce the environment in a controlled, educational lab:

  • Victim: Windows 10/11 prior to Aug 2024 patch / 24H2, IPv6 enabled.
  • Attacker: Linux VM with Python 3, Scapy.
  • Network: IPv6 connectivity between both machines on the same network segment.

PoC Logic (High-Level)

The PoC crafts a sequence of packets to trigger the underflow:

  1. Destination Options with an unrecognized option type to push error-handling paths.
  2. Fragment 1 to start fragmentation and provide payload.
  3. Fragment 2 to terminate the sequence.

The script repeats these batches while varying the Hop Limit to increase the probability of encountering the vulnerable parsing path.


Usage

  1. Identify the target IPv6 address.
  2. Update ip_addr and iface in CVE-2024-38063.py.
  3. Run the script from the attacker machine:
pip install scapy
pip install getmac
python3 CVE-2024-38063.py

If the target is vulnerable, a BSOD typically occurs within 30–60 seconds as the kernel processes malformed headers.


Mitigation

  • Apply security updates: Microsoft patch (Aug 13, 2024).
  • Disable IPv6 where patching is not possible.
  • Firewall filtering: block fragmented IPv6 packets at the perimeter.

What I Learned

  • IPv6 Header Architecture: Deepened my understanding of next-header chaining (Hop-by-Hop, Destination Options, and Fragmentation), and how nested header complexity broadens the network attack surface.
  • Kernel-Level Packet Ingestion (tcpip.sys): Observed Ring 0 packet processing firsthand. Because fragmentation reassembly and parsing occur deep inside the network driver before reaching user-mode sockets, flaws at this layer bypass host-level software controls and enable zero-click exploitation.
  • Root-Cause Vulnerability Mechanics: Analyzed how an integer underflow in header-length calculation corrupts pointer offsets, translating an arithmetic flaw into out-of-bounds kernel memory writes and system panics (BSOD).
  • Custom Packet Crafting with Scapy: Gained hands-on experience constructing non-RFC-compliant packets, injecting malformed Destination Option TLVs (Type-Length-Value), and sequencing fragments to force edge-case error handling in the target kernel.

Disclaimer

This project is for educational and research purposes only. Unauthorized testing or access to systems you do not own or have explicit permission to assess is illegal. The authors assume no responsibility for misuse.

Télécharger l’outil