Buffer overflow in Microsoft Windows and Windows Server - CVE-2020-16898
Published: October 13, 2020 / Updated: December 28, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. A remote attacker can send specially crafted ICMPv6 Router Advertisement packets, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Windows Server
How to mitigate CVE-2020-16898
Links to Public Exploits and PoC-codes
- Exploit #4962 - CVE-2020-16898-EXP-POC (CVE-2020-16898 Windows TCP/IP远程代码执行漏洞 EXP&POC) (December 28, 2020)
- Exploit #4798 - CVE-2020-16898--EXP-POC (CVE-2020-16898 Windows TCP/IP远程代码执行漏洞 EXP&POC) (November 6, 2020)
- Exploit #4766 - CVE-2020-16898 () (October 28, 2020)
- Exploit #4727 - CVE-2020-16898 (CVE-2020-16898 Windows TCP/IP远程代码执行漏洞 EXP&POC) (October 21, 2020)
- Exploit #4719 - cve-2020-16898 (PoC BSOD for CVE-2020-16898 (badneighbor)) (October 18, 2020)
- Exploit #4717 - cve-2020-16898 (PoC BSOD for CVE-2020-16898) (October 18, 2020)
- Exploit #4716 - CVE-2020-16898-exp () (October 18, 2020)