CVE-2020-16898
HIGH 8.8EPSS 10.9%
<p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client.</p><p>To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer.</p><p>The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets.</p>
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 5.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 10.94% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2020-10-16
- Updated
- 2024-08-04
Proof-of-concept exploits (12)
- 0xeb-bp/cve-2020-1689822★ · 2020-10-16
- Q1984/CVE-2020-168981★ · 2020-10-16
- ZephrFish/CVE-2020-1689822★ · 2026-07-31
- advanced-threat-research/CVE-2020-16898209★ · 2020-10-26
- corelight/CVE-2020-168989★ · 2024-09-03
- esnet-security/cve-2020-168980★ · 2020-10-15
- initconf/CVE-2020-16898-Bad-Neighbor2★ · 2020-10-22
- jiansiting/cve-2020-168989★ · 2020-10-17
- komomon/CVE-2020-16898--EXP-POC12★ · 2020-10-28
- komomon/CVE-2020-16898-EXP-POC5★ · 2020-10-28
- momika233/CVE-2020-16898-exp17★ · 2020-10-17
- ovchinic/CS-4780★ · 2022-03-28
Exploit collections (2)
- helloexp/0day/tree/master/00-CVE_EXP/CVE-2020-16898
- tzwlhack/Vulnerability/blob/main/CVE-2020-16898%20%7C%20Windows%20TCP-IP%E8%BF%9C%E7%A8%8…