Windows TCP/IP Remote Code Execution Vulnerability
msrc.microsoft.com
msrc.microsoft.com
Yay. :p
Like any valuable secret, the incentives are in the other direction on both sides.
The researcher/firm was the one that disclosed it, but I don't feel like you could conclusively say that the exploit isn't in the wild.
I suspect more of the second than the first. If it's just inactive, a compromised host can often broadcast a router advertisement or perhaps use local net addresses to compromise other hosts. A well prepared network would block ipv6 traffic on their switches, it they don't want it, but that's a big investment in capable switches.
> You cannot completely disable IPv6 as IPv6 is used internally on the system for many TCPIP tasks. For example, you will still be able to run ping ::1 after configuring this setting.
I'd be concerned their workaround is just limiting it into a local vulnerability that spyware, etc will abuse on all the systems that end up not patched because they used the workaround..
..because it uses one of the available local escalation tricks, where sending RA to ::1 could be one of those if that is a thing.
That’s just flat out wrong. No pure IPv6 deployments exist on endpoints in practice. Only in internal networks. You either run pure v4, or dual stacked v4+v6.
IPv6 is gaining some pretty solid adoption these days, but it’s not there yet. Disabling it is holding back the deployment of it, and is a problem by itself.
Whether it’s exposed to the Internet is another question, but pretty much everyone has a firewall to at least stop passive scans.
https://www.bleepingcomputer.com/news/microsoft/zero-click-w...
Which is against Microsoft's recommendations:
> Internet Protocol version 6 (IPv6) is a mandatory part of Windows Vista and Windows Server 2008 and newer versions. We do not recommend that you disable IPv6 or its components. If you do, some Windows components may not function.
* https://learn.microsoft.com/en-us/troubleshoot/windows-serve...
Is there a CVE database noscript/basic (x)html reader?
This is just some big tech-cracy abusing the script kiddy who is in all of us, poisoning us with massive kludges which obsviously only them could maintain and control, using it as trojan horse for all their toxic tech.
And adoption seems to be at 45%[0].
Actually, I was planning to switch off IPv4 but some SMTP servers are still IPv4 only and few other services (msft github for instance).
I tried 464XLAT on my home network, for the most part it worked flawlessy, aside from some IoT devices that don’t support v6 at all or are not LAT aware. So dual stack it is.
Ofc, it depends on your usage.
But what's very surprising are those Big Tech sites, with billions of $ and still IPv4 only, like msft github (and github has still its core functions working with noscript/basic (x)html browsers).
What is really bothering me is the admin of the mail server of my medical insurance company: IPv4... but that's not what is the most annoying, the most annoying: it is not white listing its client SMTP servers/client emails... this is another level of bad.
https://learn.microsoft.com/en-us/troubleshoot/windows-serve...
https://techcommunity.microsoft.com/t5/core-infrastructure-a...
Anyway, question is.. If this is mitigated by disabling IPv6 it means its IPv6 stack only issue exploit? IPv4 is safe?