cbcvebase.
CVE-2020-16898
published 2020-10-16

CVE-2020-16898: A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully…

PriorityP259high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
9.69%
95.0th percentile
A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer. The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1709>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1709_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1803>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_arm64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_x64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1909>= 10.0.0 < publicationpublication
microsoftwindows_10_version_2004>= 10.0.0 < publicationpublication
microsoftwindows_server_2016
microsoftwindows_server_2016
microsoftwindows_server_2016
microsoftwindows_server_2019>= 10.0.0 < publicationpublication
microsoftwindows_server_version_2004>= 10.0.0 < publicationpublication
msrcwindows_10_version_1709
msrcwindows_10_version_1803
msrcwindows_10_version_1809
msrcwindows_10_version_1903
msrcwindows_10_version_1909

Detection & IOCsextracted from sources · hover to see the quote

otherPalo Alto Networks Threat Prevention Threat ID 59240
commandnetsh int ipv6 set int Idx number rabaseddnsconfig=disable
snort
55942
snort
55943
snort
55979
snort
55980
snort
55982
snort
55983
snort
55984
snort
55989
snort
55990
snort
55993
snort
55994
  • Detect specially crafted ICMPv6 Router Advertisement packets targeting the Windows TCP/IP stack (RDNSS option abuse)
  • Scope detection to Windows 10 version 1709 and later (first version to support IPv6 RDNSS); earlier Windows versions are not affected
  • Check Point IPS signature name for network-level detection of exploit attempts
  • Palo Alto Networks Threat Prevention content update version 8330 includes coverage; use Threat ID 59240 for detection in NGFW logs
  • ·Mitigation (disabling IPv6 RDNSS via netsh) must be applied per-interface; verify RA Based DNS Config (RFC 6106) is disabled on each interface index
  • ·Snort rules listed cover the full October 2020 Patch Tuesday release, not exclusively CVE-2020-16898; confirm which rule SIDs specifically map to this CVE before deploying
  • ·Current exploitation leads to DoS with possibility of RCE; full RCE exploitation path may not yet be publicly confirmed at time of disclosure

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.