Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2024-38063 — PoC exploit and technical analysis for CVE-2024-38063 in the Windows IPv6 stack, built with Python and Scapy | Kitploit
ツール/GitHubGitHub/avidanmaatuk/cve-2024-38063
Vulnerability AnalysisExploitationNetwork SecurityLearning & EducationBinary ExploitationLabs & Practice
GitHubavidanmaatuk/cve-2024-38063

CVE-2024-38063

PoC exploit and technical analysis for CVE-2024-38063 in the Windows IPv6 stack, built with Python and Scapy

リポジトリを見る
11722日前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
要求された言語のコンテンツは利用できません。英語版を表示しています。

CVE-2024-38063 — Windows IPv6 Stack Vulnerability (Analysis & PoC)

Topic Focus Severity

Technical analysis and Proof-of-Concept (PoC) for CVE-2024-38063, a critical Remote Code Execution (RCE) vulnerability in the Windows IPv6 stack (tcpip.sys). Discovered by KunLun Lab, this issue is zero-click, meaning it can be triggered by specially crafted packets without user interaction.

Academic context: Final project for the “Foundations of Network Security” course.


Demo

Example BSOD


Table of Contents

  • Overview
  • Technical Summary
  • Repository Contents
  • Lab Setup
  • PoC Logic (High-Level)
  • Usage
  • Mitigation
  • What I Learned
  • Disclaimer

Overview

This repository contains:

  • a structured analysis of the vulnerability,
  • a PoC demonstration using Scapy,
  • and full course documentation and lab instructions.

Technical Summary

The core issue is an integer underflow in tcpip.sys during parsing of IPv6 Extension Headers within fragmented traffic.

  • Logic failure: header length validation fails during calculation.
  • Memory corruption: underflow leads to a buffer overflow and unsafe memory writes.
  • Impact: potential BSOD and RCE under specific conditions.

Repository Contents

  • CVE-2024-38063 Analysis.pdf — Slides covering background, root cause, and mitigations.
  • CVE-2024-38063.py — Scapy-based PoC script (demonstrates crash behavior).
  • WriteUP.pdf — Full write-up, lab requirements, and execution notes.

Lab Setup

To reproduce the environment in a controlled, educational lab:

  • Victim: Windows 10/11 prior to Aug 2024 patch / 24H2, IPv6 enabled.
  • Attacker: Linux VM with Python 3, Scapy.
  • Network: IPv6 connectivity between both machines on the same network segment.

PoC Logic (High-Level)

The PoC crafts a sequence of packets to trigger the underflow:

  1. Destination Options with an unrecognized option type to push error-handling paths.
  2. Fragment 1 to start fragmentation and provide payload.
  3. Fragment 2 to terminate the sequence.

The script repeats these batches while varying the Hop Limit to increase the probability of encountering the vulnerable parsing path.


Usage

  1. Identify the target IPv6 address.
  2. Update ip_addr and iface in CVE-2024-38063.py.
  3. Run the script from the attacker machine:
pip install scapy
pip install getmac
python3 CVE-2024-38063.py

If the target is vulnerable, a BSOD typically occurs within 30–60 seconds as the kernel processes malformed headers.


Mitigation

  • Apply security updates: Microsoft patch (Aug 13, 2024).
  • Disable IPv6 where patching is not possible.
  • Firewall filtering: block fragmented IPv6 packets at the perimeter.

What I Learned

  • IPv6 Header Architecture: Deepened my understanding of next-header chaining (Hop-by-Hop, Destination Options, and Fragmentation), and how nested header complexity broadens the network attack surface.
  • Kernel-Level Packet Ingestion (tcpip.sys): Observed Ring 0 packet processing firsthand. Because fragmentation reassembly and parsing occur deep inside the network driver before reaching user-mode sockets, flaws at this layer bypass host-level software controls and enable zero-click exploitation.
  • Root-Cause Vulnerability Mechanics: Analyzed how an integer underflow in header-length calculation corrupts pointer offsets, translating an arithmetic flaw into out-of-bounds kernel memory writes and system panics (BSOD).
  • Custom Packet Crafting with Scapy: Gained hands-on experience constructing non-RFC-compliant packets, injecting malformed Destination Option TLVs (Type-Length-Value), and sequencing fragments to force edge-case error handling in the target kernel.

Disclaimer

This project is for educational and research purposes only. Unauthorized testing or access to systems you do not own or have explicit permission to assess is illegal. The authors assume no responsibility for misuse.

ツールをダウンロード