Integer underflow in Microsoft Windows and Windows Server - CVE-2024-38063
Published: August 13, 2024 / Updated: April 25, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer underflow in Windows TCP/IP. A remote attacker can send a specially crafted request to the affected application, trigger integer underflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Windows Server
How to mitigate CVE-2024-38063
Windows Server - addressed in versions 2008 R2 6.1.7601.27277, 2008 6.0.6003.22825, 2012 R2 6.3.9600.22134, 2012 6.2.9200.25031, 2016 10.0.14393.7259, 2022 10.0.20348.2655
Links to Public Exploits and PoC-codes
- Exploit #11337 - AI-CVE-2024-38063-0-DAY (April 25, 2025)
- Exploit #11075 - CVE-2024-38063-scanner (A Python tool leveraging Shodan and Scapy to identify and exploit Windows systems vulnerable to CVE-2024-38063, enabling targeted Denial of Service attacks) (January 17, 2025)
- Exploit #10890 - CVE-2024-38063 (poc for exploiting cve-2024-38063) (November 22, 2024)
- Exploit #10883 - CVE-2024-38063 (November 22, 2024)
- Exploit #10656 - Windows TCP/IP - RCE Checker and Denial of Service (October 25, 2024)
- Exploit #10616 - CVE-2024-38063 (October 17, 2024)
- Exploit #10614 - CVE-2024-38063 (October 17, 2024)
- Exploit #10548 - cve-2024-38063 (September 27, 2024)
- Exploit #10503 - CVE-2024-38063_PoC (September 6, 2024)
- Exploit #10502 - CVE-2024-38063 (September 6, 2024)
- Exploit #10492 - Cve-2024-38063 (September 6, 2024)
- Exploit #10485 - cve-2024-38063 (September 6, 2024)
- Exploit #10473 - CVE-2024-38063 (August 30, 2024)
- Exploit #10469 - CVE-2024-38063 (August 30, 2024)
- Exploit #10452 - CVE-2024-38063-Research-Tool (This is a functional proof of concept (PoC) for CVE-2024-38063. However, it's important to note that this CVE is theoretical and not exploitable in a real-world scenario. To enhance understanding for learners, I have develope (August 30, 2024)