CVE-2024-38063Disclosure(microsoft / windows_10_1507)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Windows TCP/IP Remote Code Execution Vulnerability

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-191

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-06-30); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2008

2 versions affected across 15 products

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-02-26: 1Mentions · 2026-04-01: 1Mentions · 2026-05-15: 1Mentions · 2026-06-30: 2Mentions · 2026-09-09: 1Mentions · 2026-09-11: 1Mentions · 2026-09-12: 1Exploit Tool / Code · 2026-09-11: 1Active Exploitation · 2026-09-11: 1Technical Details · 2026-06-30: 2Technical Details · 2026-09-12: 102-2604-0105-1506-3009-0909-1109-12
Signal classification3 categories
Disclosure
450.0%
General
337.5%
Active Exploitation
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-261
General1
2026-04-011
Disclosure1
2026-05-151
General1
2026-06-302
Disclosure2
2026-09-091
General1
2026-09-111
Active Exploitation1
2026-09-121
Disclosure1
Full discourse8 posts
  • 𝕡𝕨𝕟𝕚𝕖@0day_ninja
    Disclosure

    Integer overflow this Integer overflow that Ever heard of interger underflow? CVE-2024-38063 is a zero-click Windows TCP/IP remote code execution vulnerability caused by an integer underflow in the kernel driver responsible for handling IPv6 packets. An attacker sends specially crafted packets and gets code execution with no interaction from the target.

    Post summary

    CVE-2024-38063 is a zero-click remote code execution vulnerability due to an integer underflow in the Windows IPv6 kernel driver, enabling attackers to run code via specially crafted packets.

    44048193.5K
    6.5K followersView on X
  • 𝕡𝕨𝕟𝕚𝕖@0day_ninja
    Disclosure

    August 22, 2024 Advisory: Microsoft Windows IPv6 TCP/IP RCE [CVE-2024-38063] - Censys https://share.google/ZpDoKhaZSZtK8hXNL

    Post summary

    A Microsoft Windows IPv6 TCP/IP Remote Code Execution vulnerability (CVE-2024-38063) was publicly disclosed on August 22, 2024 via a Censys advisory link, detailing RCE but providing no PoC, exploit, or patch information.

    20042401
    6.5K followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    A list of Microsoft Windows CVE identifiers is provided with no additional information.

    10000106
    15 followersView on X
  • VampireXRay@VampireXray
    Disclosure

    CVE 100,000$ Bounty? Why? https://medium.com/@VampireXRay/cve-2024-38063-a-deep-dive-into-the-ipv6-kernel-pool-vulnerability-72cc11c93978

    Post summary

    The Medium article title indicates a new CVE‑2024‑38063 related to an IPv6 kernel pool flaw and mentions a potential $100k bounty, but no technical or exploit details are provided within the given text.

    00010121
    57 followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam
    Disclosure

    @NitinGavhane_ cve-2024-38063. black-box scanners miss auth bypasses in proprietary routers. can you trace taint without the repo?

    Post summary

    The tweet points out that CVE‑2024‑38063 involves an authentication bypass in proprietary routers, noting that black‑box scanners miss this flaw.

    00000179
    1.3K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Multiple Chinese APT groups coordinated deployment of the BlueMoon exploit kit, chaining three zero-days (CVE-2024-7971, CVE-2024-8198, CVE-2024-38063) for browser compromise and Windows privilege escalation. Post-compromise lateral movement across targeted aerospace and defense networks highlights the value of runtime segmentation to contain multi-stage breach chains. #ZeroDay #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/bluemoon-exploit-kit-chrome-windows-zero-days-2026

    Post summary

    Multiple Chinese APT groups deployed the BlueMoon exploit kit, chaining CVE‑2024‑7971, CVE‑2024‑8198 and CVE‑2024‑38063 for browser compromise and Windows privilege escalation, demonstrating active exploitation and lateral movement within aerospace and defense networks.

    0000060
    2.0K followersView on X
  • nol@nol_tech
    General

    @UK_Daniel_Card microsoft is infamous for estimating "attack-complexity" completely randomly; they did the same for cve-2024-38063 and many others until I see a POC; i'm not believing it

    Post summary

    The tweet expresses doubt about Microsoft's assessment of CVE‑2024‑38063 and says a proof‑of‑concept is needed to be convinced, offering no additional technical or exploit information.

    00000456
    838 followersView on X
  • Miranox@Miranox22
    General

    @SphinxWyvern @TechBinary99 @Pirat_Nation I don't think monitoring can solve critical vulnerabilities such as this one. https://www.picussecurity.com/resource/blog/cve-2024-38063-remote-kernel-exploitation-via-ipv6-in-windows

    Post summary

    The tweet comments on a critical vulnerability (CVE-2024-38063) but offers no technical details, PoC, or exploitation information.

    0000064
    202 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---

Explore more