cbcvebase.
CVE-2021-24094
published 2021-02-25

CVE-2021-24094: Windows TCP/IP Remote Code Execution Vulnerability

PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
22.14%
97.4th percentile
Windows TCP/IP Remote Code Execution Vulnerability

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1607>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1803>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1909>= 10.0.0 < publicationpublication
microsoftwindows_10_version_2004>= 10.0.0 < publicationpublication
microsoftwindows_10_version_20h2>= 10.0.0 < publicationpublication
microsoftwindows_7>= 6.1.0 < publicationpublication
microsoftwindows_7_service_pack_1>= 6.1.0 < publicationpublication
microsoftwindows_8.1>= 6.3.0 < publicationpublication
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < publicationpublication
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < publicationpublication
microsoftwindows_server_2008_service_pack_2>= 6.0.0 < publicationpublication
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.0 < publicationpublication
microsoftwindows_server_2012_r2>= 6.3.0 < publicationpublication
microsoftwindows_server_2016
microsoftwindows_server_2016

Detection & IOCsextracted from sources · hover to see the quote

commandnetsh int ipv6 set global reassemblylimit=0
commandnetsh int ipv4 set global sourceroutingbehavior=drop
commandshow counter global filter delta yes | match flow_parse_ip6
commandshow counter global filter delta yes | match flow_dos_pf_badoption
snort
57103, 57104, 57106 - 57108, 57123 and 57128
  • Detect crafted IPv6 packets with multiple headers, invalid headers, or multiple fragment headers targeting Windows TCP/IP stack (CVE-2021-24094 DoS vector).
  • Monitor for IPv6 packet drops matching flow_parse_ip6_truncated, flow_parse_ip6_invalid_routing_ext_hdr, and flow_parse_ip6_frag_nested counters as indicators of active exploitation attempts.
  • Monitor for IPv4 packets carrying Security Options (Type 130) in the first fragment followed by LSRR (Type 131) or SSRR (Type 137) options in a second fragment — the specific fragmentation pattern exploited in the related RCE CVE-2021-24074.
  • Monitor for IPv4 Zone Protection counter hits on flow_dos_pf_badoption, flow_dos_pf_strictsource as indicators of source-routing-based attack packets being sent to Windows hosts.
  • Block or alert on IPv6 fragmented packets at edge devices (firewall/load balancer); host-based firewalls are explicitly noted as insufficient protection for CVE-2021-24094.
  • ·The Snort rule IDs (57103, 57104, 57106-57108, 57123, 57128) cover multiple February 2021 Patch Tuesday CVEs collectively, not exclusively CVE-2021-24094; confirm which rule IDs map specifically to CVE-2021-24094 before deploying.
  • ·The workaround command 'netsh int ipv6 set global reassemblylimit=0' drops all out-of-order IPv6 fragments and may cause packet loss in legitimate traffic; test before deploying in production.
  • ·Windows systems configured with only IPv6 link-local addresses are not remotely exploitable for CVE-2021-24094, as link-local addresses are not routable on the internet.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.