Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

CVE-2024-38063 is a critical Windows TCP/IP vulnerability that can allow remote code execution when an attacker sends specially crafted IPv6 packets to an affected system. It requires IPv6 to be enabled, but does not require authentication or a user to click anything. Install the applicable Microsoft security update or a later cumulative update; disabling IPv6 is, at most, a temporary mitigation.

What is CVE-2024-38063?

Microsoft disclosed CVE-2024-38063 on August 13, 2024, as a Windows TCP/IP Remote Code Execution Vulnerability. It affects packet processing in the Windows TCP/IP stack and concerns IPv6 traffic. An unauthenticated attacker may be able to send specially crafted IPv6 packets to a vulnerable Windows system and cause remote code execution. The attack does not require a victim to open a file, visit a website, or approve a prompt. NIST’s CVE record and CERT-EU’s advisory describe the issue and attack conditions.

“Zero-click” is a shorthand for the lack of required user interaction, not a guarantee that every Windows computer can be compromised from anywhere. An attacker still needs a network path by which the relevant IPv6 traffic can reach the host, and the host must be running an affected, unpatched product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why is it rated Critical?

NIST records Microsoft’s CVSS v3.1 score as 9.8 Critical, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The score describes severity under the CVSS model; it does not establish that a particular system has been attacked or that exploitation succeeds in every network.

CVSS metric Value Meaning
Attack vector Network The attacker can target the system over a network rather than needing local access.
Attack complexity Low The metric does not assume unusual conditions that make exploitation difficult.
Privileges required None An attacker does not need an account on the target.
User interaction None No victim action is required.
Scope Unchanged The impact is assessed within the vulnerable system’s security authority.
Confidentiality High Successful exploitation could put data confidentiality at risk.
Integrity High Successful exploitation could allow significant changes to system data or behavior.
Availability High Successful exploitation could disrupt system availability.

The network access and absence of authentication make this more urgent than a flaw that requires a local account or user action. The actual exposure of a given host still depends on its Windows release, patch state, IPv6 configuration, and network reachability.

How does the flaw work at a high level?

NIST lists the weakness as CWE-191, an integer underflow. An underflow occurs when arithmetic produces a value below the minimum representable range. In packet-processing code, an incorrect size or length calculation can leave software working with an invalid value. If that value affects parsing, allocation, copying, or buffer boundaries, memory corruption can result. A flaw in a core networking component is particularly serious because the component handles traffic as part of the operating system.

This is a conceptual explanation, not a confirmed description of a specific vulnerable function or packet layout. An academic reverse-engineering paper discusses processing chains of coalesced IPv6 packets and a feature flag introduced by the patch, but that analysis is not Microsoft’s official root-cause description. Read the academic analysis.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which Windows versions may be affected?

The affected-product records include Windows 10 release branches, Windows 11 21H2, 22H2, and 23H2, and multiple Windows Server branches, including Server 2008 and 2008 R2, Server 2012 and 2012 R2, Server 2016, Server 2019, and Server 2022. Server Core variants are also relevant where listed. This is not a claim that every edition or installation of those releases is currently vulnerable: product, architecture, servicing branch, support status, and installed cumulative updates all matter.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

For the exact product-specific affected status and applicable update, use Microsoft’s Security Update Guide entry for CVE-2024-38063. The NVD record includes version data and change history, but Windows cumulative updates supersede earlier updates, so an August 2024 build threshold or KB number should not be treated as the sole current compliance test.

Does an attacker need IPv6 to be enabled?

Yes. New Zealand’s National Cyber Security Centre says the vulnerability requires IPv6 to be enabled and lists disabling IPv6 as a mitigation. NCSC’s alert also summarizes affected Windows families.

An organization’s description of its network as “IPv4-only” does not by itself establish that IPv6 is disabled on every Windows interface. IPv6 may remain enabled even when administrators do not intentionally route production traffic over it. Determine the host’s actual adapter bindings and whether IPv6 traffic can reach it; do not rely only on whether a user sees an IPv6 address in a graphical network view.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was CVE-2024-38063 exploited in the wild?

The NVD record’s June 17, 2026 CISA-ADP enrichment reports exploitation as “poc,” automatable as “yes,” and technical impact as “total.” This is an assessment indicating public proof-of-concept status in the record; it is not, by itself, proof of widespread real-world exploitation, ransomware use, or compromise of a particular machine. The supplied authoritative records do not establish those stronger claims. Check the NVD record for its current metadata.

Rank #3

A proof of concept, a high severity score, confirmed exploitation in the wild, and inclusion in CISA’s Known Exploited Vulnerabilities catalog are different things. Do not infer one from another. For current catalog status, consult CISA’s KEV catalog.

How should administrators remediate it?

  1. Inventory the affected estate. Identify Windows clients and servers, including Server Core, virtual machines, offline or dormant machines, and deployment images. Record product, edition, architecture, servicing branch, IPv6 state, and update status.
  2. Install the applicable Microsoft security update. Use the product-specific guidance in the Microsoft Security Update Guide, or deploy a later cumulative update that supersedes it. Use the organization’s normal Windows Update or managed deployment channel; do not download an unverified third-party package.
  3. Reboot when required and verify. Check the resulting OS build or package state after installation rather than relying only on a KB search or the update-history screen.
  4. Rescan and close exceptions. Confirm compliance in endpoint-management or vulnerability-management reporting. Track any system that cannot be patched, its compensating controls, owner, and deadline.
  5. Update images and recovery systems. Patch golden images and offline or disaster-recovery systems so they do not reintroduce an unpatched installation when deployed.

Prioritize internet-facing or otherwise untrusted-network-reachable Windows systems with IPv6 enabled, followed by high-value servers and hosts whose patch status cannot be confirmed. Network reachability, role, and the ability to patch should guide ordering; the score alone does not tell you which individual host is reachable.

How can you check a Windows system?

Read the operating-system build

Run this in PowerShell to collect the product name, version, and build:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber

For a quick local view, run winver. For remote or fleet collection, this CIM query returns the operating-system caption, version, and build:

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Get-CimInstance Win32_OperatingSystem | Select-Object Caption, Version, BuildNumber

Compare the result with the current Microsoft update guidance for that exact Windows branch. A later cumulative build may include the fix even when the original August 2024 KB is not the most useful identifier.

Review recent hotfix inventory

This command lists recent entries exposed through the Windows quick-fix engineering inventory:

Get-CimInstance Win32_QuickFixEngineering | Sort-Object InstalledOn -Descending | Select-Object -First 20 HotFixID, InstalledOn, Description

Use it as supporting evidence, not the only compliance check. Servicing technologies and cumulative-update supersedence can make a historical KB lookup incomplete.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect the TCP/IP driver version as a secondary check

(Get-Item "$env:windirSystem32driverstcpip.sys").VersionInfo | Select-Object FileVersion, ProductVersion

Do not use this file version alone as the compliance authority; compare it with Microsoft’s product-specific servicing guidance or an enterprise patch inventory.

Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

Check IPv6 adapter bindings

Get-NetAdapterBinding -ComponentID ms_tcpip6 | Select-Object Name, DisplayName, Enabled

This shows the IPv6 binding state by adapter. It helps assess the IPv6 condition but does not prove that the system is patched.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What if Windows Update fails?

  • Confirm that the system is on a supported servicing branch and that the package matches the exact product, architecture, and branch.
  • Check available disk space, pending restarts, Windows Update history, and servicing logs, including CBS logs.
  • Schedule another installation attempt in a maintenance window. For managed environments, use the established patch-management platform, such as Windows Update for Business, WSUS, Configuration Manager, Intune, or an equivalent tool.
  • If using Microsoft Update Catalog or enterprise deployment tooling, verify package applicability before deployment. Do not mix packages intended for different Windows releases.
  • If an update rolls back, investigate servicing-stack health, driver conflicts, pending restarts, and component-store issues. These diagnostic commands check system health but do not install the CVE fix:
DISM.exe /Online /Cleanup-Image /ScanHealth
sfc.exe /scannow

After a successful installation and restart, recheck the OS build and your management or vulnerability scanner’s result.

Should you disable IPv6?

Disabling IPv6 can remove the required protocol condition for this vulnerability, according to New Zealand’s NCSC, but it is a temporary mitigation rather than the preferred remediation. Microsoft components and organizational services may rely on IPv6 or behave differently when it is disabled. Potentially affected areas include domain services, DNS, VPNs, remote management, network discovery, applications, and cloud connectivity. The impact varies by environment, so blanket enterprise-wide disablement is not a safe default.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If an unpatched system must be temporarily mitigated, assess the change with the system owner, test dependent services, record which hosts and interfaces are affected, and set a deadline to patch and restore the intended IPv6 configuration. A host with IPv6 disabled is still unpatched and should not be treated as permanently compliant.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$294.98
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99

Enterprise response checklist

  • Discover Windows clients, servers, Server Core hosts, virtual machines, offline devices, and deployment images.
  • Identify affected product branches and compare installed builds with Microsoft’s current product-specific update guidance.
  • Assess IPv6 bindings and network paths from untrusted or semi-trusted networks; prioritize reachable, high-value systems.
  • Deploy the applicable update or a superseding cumulative update, then reboot where required.
  • Verify by build or package inventory and rescan the fleet; investigate discrepancies between endpoint reports and actual host state.
  • Track temporary IPv6 mitigations as time-limited exceptions with owners, testing, and rollback dates.
  • Patch golden images and recovery media, and revisit dormant systems before returning them to service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.