Windows Critical ICMP Remote Code Execution Vulnerability
msrc.microsoft.com
msrc.microsoft.com
I can't think of any... Which in turn means that most systems probably aren't vulnerable. On windows I think you need admin rights to open a raw socket, which means that only admins can pwn the machine...
I reverse engineered some antivirus products myself and the quality of most AVs is pretty bad. AFL (American Fuzzy Lop) without a custom mutator crashed some of them in less than 15 minutes at the most trivial parts like parsing a PE-file.
Also snakeoil-features like "anti-rootkit scanner" just compare hashes (sometimes MD5-hashes) of installed drivers. In past a rootkit could circumvent such scanner with IAT-hooking. In 2023 those scanners are obsolete anyway.
Also antivirus 0-days are far cheaper than for other software.*
What is a "raw socket" in this context?
A raw socket allows creation/consumption of bespoke packet types (i.e. not Tcp/Udp). In this case ICMP.
And here they explain that if you use SOCK_RAW, you should look out for bad datagrams:
https://learn.microsoft.com/en-us/windows/win32/winsock/tcp-...