CVE-2020-16898

HIGH

Microsoft Windows 10 - Remote Code Execution

Title source: rule
STIX 2.1

Description

<p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client.</p> <p>To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer.</p> <p>The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets.</p>

Exploits (14)

nomisec WORKING POC 209 stars
by advanced-threat-research · poc
https://github.com/advanced-threat-research/CVE-2020-16898
nomisec SUSPICIOUS 22 stars
by ZephrFish · poc
https://github.com/ZephrFish/CVE-2020-16898
nomisec WORKING POC 21 stars
by 0xeb-bp · poc
https://github.com/0xeb-bp/cve-2020-16898
nomisec WORKING POC 19 stars
by momika233 · poc
https://github.com/momika233/CVE-2020-16898-exp
nomisec WORKING POC 13 stars
by komomon · poc
https://github.com/komomon/CVE-2020-16898--EXP-POC
nomisec WRITEUP 9 stars
by corelight · poc
https://github.com/corelight/CVE-2020-16898
nomisec WORKING POC 9 stars
by jiansiting · poc
https://github.com/jiansiting/cve-2020-16898
nomisec WORKING POC 5 stars
by komomon · poc
https://github.com/komomon/CVE-2020-16898-EXP-POC
nomisec STUB 2 stars
by initconf · poc
https://github.com/initconf/CVE-2020-16898-Bad-Neighbor
nomisec SCANNER 2 stars
by Maliek · poc
https://github.com/Maliek/CVE-2020-16898_Check
nomisec WORKING POC 1 stars
by Q1984 · poc
https://github.com/Q1984/CVE-2020-16898
nomisec SCANNER
by CPO-EH · poc
https://github.com/CPO-EH/CVE-2020-16898_Checker
nomisec WORKING POC
by CPO-EH · poc
https://github.com/CPO-EH/CVE-2020-16898_Workaround
nomisec WRITEUP
by esnet-security · poc
https://github.com/esnet-security/cve-2020-16898

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.3269
EPSS Percentile 96.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (10)
microsoft/windows_10 1709
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1903
microsoft/windows_10 1909
microsoft/windows_10 2004
microsoft/windows_server_2016 1903
microsoft/windows_server_2016 1909
microsoft/windows_server_2016 2004
microsoft/windows_server_2019
Published Oct 16, 2020
Tracked Since Feb 18, 2026