CVE-2020-16898
published 2020-10-16CVE-2020-16898: A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully…
PriorityP259high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
9.69%
95.0th percentile
A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client.
To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer.
The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| msrc | windows_10_version_1709 | — | — |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1903 | — | — |
| msrc | windows_10_version_1909 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
55942
snort↗
55943
snort↗
55979
snort↗
55980
snort↗
55982
snort↗
55983
snort↗
55984
snort↗
55989
snort↗
55990
snort↗
55993
snort↗
55994
- →Detect specially crafted ICMPv6 Router Advertisement packets targeting the Windows TCP/IP stack (RDNSS option abuse) ↗
- →Scope detection to Windows 10 version 1709 and later (first version to support IPv6 RDNSS); earlier Windows versions are not affected ↗
- →Check Point IPS signature name for network-level detection of exploit attempts ↗
- →Palo Alto Networks Threat Prevention content update version 8330 includes coverage; use Threat ID 59240 for detection in NGFW logs ↗
- ·Mitigation (disabling IPv6 RDNSS via netsh) must be applied per-interface; verify RA Based DNS Config (RFC 6106) is disabled on each interface index ↗
- ·Snort rules listed cover the full October 2020 Patch Tuesday release, not exclusively CVE-2020-16898; confirm which rule SIDs specifically map to this CVE before deploying ↗
- ·Current exploitation leads to DoS with possibility of RCE; full RCE exploitation path may not yet be publicly confirmed at time of disclosure ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8vrv-2fm5-wpvr: A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets, aka 'Windows TCP/IP
ghsa_unreviewed·2022-05-24
CVE-2020-16898 [HIGH] GHSA-8vrv-2fm5-wpvr: A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets, aka 'Windows TCP/IP
A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets, aka 'Windows TCP/IP Remote Code Execution Vulnerability'.
Microsoft
Windows TCP/IP Remote Code Execution Vulnerability
vendor_msrc·2020-10-13·CVSS 8.8
CVE-2020-16898 [HIGH] Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client.
To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer.
The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets.
FAQ: Why was the Exploitability Index rating for this vulnerability lowered from “1 - Exploitation More Likely” to “2 – Exploitation Less Likely”?
The presence of exploit mitigations (specifically /GS
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch now
blogs_bleepingcomputer·2024-08-14·CVSS 9.8
[CRITICAL] Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch now
## Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch now
## Sergiu Gatlan
As Microsoft explained in its Tuesday advisory, unauthenticated attackers can exploit the flaw remotely in low-complexity attacks by repeatedly sending IPv6 packets that include specially crafted packets.
Microsoft also shared its exploitability assessment for this critical vulnerability, tagging it with an "exploitation more likely" label, which means that threat actors could create exploit code to "consistently exploit the flaw in attacks."
"Moreover, Microsoft is aware of past instances of this type of vulnerability being exploited. This would make it an attractive target for attackers, and therefore more likely that exploits could be created," Redmond explains .
"As such, customers w
Qualys
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
blogs_qualys·2022-08-23
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
## Table of Contents
Why Are Zero-Day Attacks/Exploits so Dangerous?
How Qualys Policy Compliance Helps Combat Zero-Day Threats
Benefit of Qualys Policy Compliance for Zero-Day Threats
Summary
Getting Started
Contributors
Zero-day vulnerability attacks have emerged as a major cybersecurity threat in the last few years. Organizations most often targeted include large enterprises and government/Federal agencies. However, any organization, regardless of its size, business, or industry, is a potential target for zero-day threats.
Most notably, already publicly disclosed. This means that one out of every four zero-day exploits detected could potentially have been avoided if a more thorough investigation and patching effort had been pursued. In 2021, around 58 zero-day vulnerabilities we
Checkpoint
19th October – Threat Intelligence Bulletin
blogs_checkpoint·2020-10-19
CVE-2020-16898 19th October – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th October – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 19th October 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Researchers and telecom companies have partnered to execute a coordinated attack aimed at disrupting the infamous Trickbot botnet and Malware-as-a-Service. A Court order granted the researchers control over the botnet’s infrastructure. However, the botnet was not fully disabled.
Dickey’s Barbeque Restaurant, an Am
Trendmicro
Microsoft's Patch Tuesday update for October has a relatively smaller number of patches. After a few months where the number of bug fixes exceeded the 100-mark, October’s round of updates stood at 87,
blogs_trendmicro·2020-10-14·CVSS 7.5
[HIGH] Microsoft's Patch Tuesday update for October has a relatively smaller number of patches. After a few months where the number of bug fixes exceeded the 100-mark, October’s round of updates stood at 87,
# Smaller October Patch Tuesday Fixes TCP/IP, RDP Bugs
Microsoft's Patch Tuesday update for October has a relatively smaller number of patches. After a few months where the number of bug fixes exceeded the 100-mark, October’s round of updates stood at 87, containing fixes for eleven that were rated as Critical.
By: Trend Micro Research
2020/10/14
Read time: ( words)
Save to Folio
Microsoft's Patch Tuesday update for October has a relatively smaller number of patches. After a few months where the number of bug fixes exceeded the 100-mark, October’s round of updates stood at 87, containing fixes for eleven that were rated as Critical.
## Critical TCP/IP vulnerabilities lead the way
Two of the more notable vulnerabilities that were addressed involved TCP/IP. The first, CVE-2020-16898,
Unit42
Threat Brief: Microsoft Vulnerability CVE-2020-16898
blogs_unit42·2020-10-14·CVSS 8.8
CVE-2020-16898 [HIGH] Threat Brief: Microsoft Vulnerability CVE-2020-16898
## Executive Summary
In October 2020, during Microsoft’s Patch Tuesday, a security update (CVE-2020-16898) addressed a critical vulnerability discovered in IPv6 Router Advertisement Options (called “DNS RA options”). This vulnerability resides within the Windows TCP/IP stack that is responsible for handling RA packets. Current exploitation leads to a Denial of Service (DoS) with the possibility of remote code execution.
This vulnerability affects multiple Windows versions that support IPv6 RDNSS, which was added to Windows starting with Windows 10, version 1709.
## Mitigation Actions for CVE-2020-16898
As always, we recommend that our customers patch their system as soon as possible. Until a patch can be applied, Microsoft has published guidance that can be used to mitigate this vulner
Qualys
Microsoft Windows TCP/IP Remote Code Execution Vulnerability (CVE-2020-16898) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
blogs_qualys·2020-10-14·CVSS 8.8
CVE-2020-16898 [HIGH] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (CVE-2020-16898) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
On October 13, 2020, Microsoft fixed a critical remote code execution vulnerability in the Windows TCP/IP stack for handling ICMPv6 Router Advertisement packets. While Microsoft ranks this vulnerability as “Exploitation More Likely,” we may see a proof-of-concept released soon. The security issue has received a critical severity rating score of 9.8 based on the CVSS v3 scoring system.
#### Vulnerability Details:
McAfee Advanced Threat Research released a test script to demonstrate Denial of Service that causes immediate BSOD (Blue Screen of Death); however, it could potentially lead to remote code execution and is capable of being weaponized into a chain reaction allowing attacks to spread from one vulnerable machine to another (wormable).
IPv6 router advertisement packet with a RDNSS (
Unit42
Threat Brief: Microsoft Vulnerability CVE-2020-16898
blogs_unit42·2020-10-14·CVSS 8.8
CVE-2020-16898 [HIGH] Threat Brief: Microsoft Vulnerability CVE-2020-16898
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Microsoft Vulnerability CVE-2020-16898
Mike Harbison
Brandon Young
Published: October 14, 2020
High Profile Threats
Vulnerabilities
Bad Neighbor
CVE-2020-16898
Microsoft
## Executive Summary
In October 2020, during Microsoft’s Patch Tuesday, a security update ( CVE-2020-16898 ) addressed a critical vulnerability discovered in IPv6 Router Advertisement Options (called “DNS RA options”). This vulnerability resides within the Windows TCP/IP stack that is responsible for handling RA packets. Current exploitation leads to a Denial of Service (DoS) with the possibility of remote code execution.
This vulnerability affects multiple Windows versions that support IPv6 RDNSS, which was added to Windows star
Qualys
Microsoft Windows TCP/IP Remote Code Execution Vulnerability (CVE-2020-16898) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
blogs_qualys·2020-10-14·CVSS 8.8
[HIGH] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (CVE-2020-16898) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
On October 13, 2020, Microsoft fixed a critical remote code execution vulnerability in the Windows TCP/IP stack for handling ICMPv6 Router Advertisement packets. While Microsoft ranks this vulnerability as “Exploitation More Likely,” we may see a proof-of-concept released soon. The security issue has received a critical severity rating score of 9.8 based on the CVSS v3 scoring system.
## Vulnerability Details:
McAfee Advanced Threat Research released a test script to demonstrate Denial of Service that causes immediate BSOD (Blue Screen of Death); however, it could potentially lead to remote code execution and is capable of being weaponized into a chain reaction allowing attacks to spread from one vulnerable machine to another (wormable).
IPv6 router advertisement packet with a RDNSS (Re
Qualys
October 2020 Patch Tuesday – 87 Vulnerabilities, 11 Critical, SharePoint, TCP/IP Stack, Graphics, Adobe Vulns | Qualys
blogs_qualys·2020-10-13·CVSS 8.8
[HIGH] October 2020 Patch Tuesday – 87 Vulnerabilities, 11 Critical, SharePoint, TCP/IP Stack, Graphics, Adobe Vulns | Qualys
This month’s Microsoft Patch Tuesday addresses 87 vulnerabilities with 11 of them labeled as Critical. The 11 Critical vulnerabilities cover TCP/IP Stack, SharePoint, Windows Camera Codec Pack, Graphics and several other workstation vulnerabilities. Adobe issued patches today for Adobe Flash Player.
### Workstation Patches
Continuing the trend, today’s Patch Tuesday fixes many vulnerabilities that impact workstations. The Windows Camera Codec, GDI+, Browser, Hyper-V, Outlook, Media Foundation and Graphics components vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### Windows TCP/IP RCE
An extremely critical R
Tenable
Microsoft’s October 2020 Patch Tuesday Addresses 87 CVEs including “Bad Neighbor” Windows TCP/IP Vulnerability (CVE-2020-16898)
blogs_tenable·2020-10-13·CVSS 8.8
[HIGH] Microsoft’s October 2020 Patch Tuesday Addresses 87 CVEs including “Bad Neighbor” Windows TCP/IP Vulnerability (CVE-2020-16898)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday for Oct. 2020 — Snort rules and prominent vulnerabilities
blogs_talos·2020-10-13·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for Oct. 2020 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Alex McDonnell and Nick Biasini.
Microsoft released its monthly security update Tuesday, disclosing just under 100 vulnerabilities across its array of products.
Fourteen of the vulnerabilities are considered “critical" while the vast remainder are ranked as “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products including the SharePoint document management system, Azure Sphere and the Windows camera codec, which allows users to view a variety of video files on their machines.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For complete
Talos
Microsoft Patch Tuesday for Oct. 2020 — Snort rules and prominent vulnerabilities
blogs_talos·2020-10-13·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for Oct. 2020 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Oct. 2020 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Alex McDonnell and Nick Biasini.
Microsoft released its monthly security update Tuesday, disclosing just under 100 vulnerabilities across its array of products.
Fourteen of the vulnerabilities are considered “critical" while the vast remainder are ranked as “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products including the SharePoint document management system, Azure Sphere and the Windows camera codec, which allows users to view a variety of video files on their machines.
Talos also released a new set
Krebs
Microsoft Patch Tuesday, October 2020 Edition
blogs_krebs·2020-10-13·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, October 2020 Edition
It’s Cybersecurity Awareness Month! In keeping with that theme, if you (ab)use Microsoft Windows computers you should be aware the company shipped a bevy of software updates today to fix at least 87 security problems in Windows and programs that run on top of the operating system. That means it’s once again time to backup and patch up.
Eleven of the vulnerabilities earned Microsoft’s most-dire “critical” rating, which means bad guys or malware could use them to gain complete control over an unpatched system with little or no help from users.
Worst in terms of outright scariness is probably CVE-2020-16898, which is a nasty bug in Windows 10 and Windows Server 2019 that could be abused to install malware just by sending a malformed packet of data at a vulnerable system. CVE-2020-16898 earn
Qualys
October 2020 Patch Tuesday – 87 Vulnerabilities, 11 Critical, SharePoint, TCP/IP Stack, Graphics, Adobe Vulns
blogs_qualys·2020-10-13·CVSS 8.8
[HIGH] October 2020 Patch Tuesday – 87 Vulnerabilities, 11 Critical, SharePoint, TCP/IP Stack, Graphics, Adobe Vulns
This month’s Microsoft Patch Tuesday addresses 87 vulnerabilities with 11 of them labeled as Critical. The 11 Critical vulnerabilities cover TCP/IP Stack, SharePoint, Windows Camera Codec Pack, Graphics and several other workstation vulnerabilities. Adobe issued patches today for Adobe Flash Player.
## Workstation Patches
Continuing the trend, today’s Patch Tuesday fixes many vulnerabilities that impact workstations. The Windows Camera Codec, GDI+, Browser, Hyper-V, Outlook, Media Foundation and Graphics components vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## Windows TCP/IP RCE
An extremely critical Rem
Krebs
Microsoft Patch Tuesday, October 2020 Edition
blogs_krebs·2020-10-13·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, October 2020 Edition
It’s Cybersecurity Awareness Month! In keeping with that theme, if you (ab)use Microsoft Windows computers you should be aware the company shipped a bevy of software updates today to fix at least 87 security problems in Windows and programs that run on top of the operating system. That means it’s once again time to backup and patch up.
Eleven of the vulnerabilities earned Microsoft’s most-dire “critical” rating, which means bad guys or malware could use them to gain complete control over an unpatched system with little or no help from users.
Worst in terms of outright scariness is probably CVE-2020-16898 , which is a nasty bug in Windows 10 and Windows Server 2019 that could be abused to install malware just by sending a malformed packet of data at a vulnerable system. CVE-2020-16898 ear
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
Zscaler
Zscaler protects against 4 new vulnerabilities for Microsoft
blogs_zscaler·CVSS 8.8
[HIGH] Zscaler protects against 4 new vulnerabilities for Microsoft
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
arxiv_fulltext·2024-07-31
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Raveen Kanishka Jayalath*
University of Adelaide, Australia
[email protected]
Hussain Ahmad* *Authors contributed equally to this work. Corresponding author.
University of Adelaide, Australia
[email protected]
Diksha Goel
CSIRO's Data61, Australia
[email protected]
3cmMuhammad Shuja Syed
3cmSLB, USA
[email protected]
Faheem Ullah
University of Adelaide, Australia
[email protected]
plain
## Abstract
Microservice architectures are revolutionizing both small businesses and large corporations, igniting a new era of innovation with their exceptional advantages in maintainability, reusability, and scalability. However, these benefits come w
2020-10-16
Published