CVE-2021-24074
vulnerability analysis and mitigation

Overview

Windows TCP/IP Remote Code Execution Vulnerability (CVE-2021-24074) was discovered and disclosed by Microsoft in February 2021. This critical vulnerability affects the TCP/IP implementation across all Windows versions, specifically related to IPv4 source routing functionality (MSRC Blog).

Technical details

The vulnerability is a complex Remote Code Execution (RCE) flaw in Microsoft's implementation of TCP/IP. It received a CVSS score of 8.0, indicating high severity (AV:N/AC:L/Au:N/C:P/I:P/A:P). The technical complexity of the vulnerability makes it difficult to create functional exploits (MSRC Blog, Rapid7).

Impact

If successfully exploited, this vulnerability could allow remote attackers to execute arbitrary code on affected systems. Additionally, it could be leveraged for Denial of Service (DoS) attacks, potentially causing system crashes resulting in the Blue Screen of Death on Windows systems directly exposed to the internet with minimal network traffic (MSRC Blog).

Exploitability

Microsoft assessed that while creating functional RCE exploits would be complex and unlikely in the short term, DoS exploits could be developed more quickly. At the time of disclosure, there was no evidence that this vulnerability was known to any third party or actively exploited in the wild (MSRC Blog).

Mitigation and workarounds

Microsoft released security updates to address this vulnerability. For systems where immediate patching isn't practical, a workaround involves hardening against the use of Source Routing, which can be applied through Group Policy or by running a NETSH command without requiring a reboot. Additionally, IPv4 Source Routing requests can be blocked on edge devices such as load balancers or firewalls (MSRC Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management