Advisory 13

TLP Rating: Clear

Critical vulnerabilities in Microsoft Windows TCP/IP stack

CERT Vanuatu (CERTVU) and the Office of the Chief Information was alerted of this vulnerabilities by its international partners.

The CERTVU office would like to advise it’s constituents on critical vulnerabilities in Microsoft Windows TCP/IP stack. Microsoft in its February 2021 monthly security update addressed several vulnerabilities in the TCP/IP stack. There are two critical vulnerabilities in particular that could allow an attacker to gain Remote Code Execution (RCE) access on vulnerable Windows devices. The vulnerabilities affects IPv4 and IPv6 respectively.

What it means

Microsoft Security Response Centre (MSRC) has stated the two RCE vulnerabilities are complex to exploit. It is likely that attackers will be able to execute Denial-of-Service (DoS) exploits more quickly so it is critical that users, organizations and institutions apply the latest Windows Security updates as soon as possible.

 

References

1. https://msrc-blog.microsoft.com/2021/02/09/multiple-security-updates-affecting-tcp-ip/
2. https://www.cert.govt.nz/it-specialists/advisories/critical-vulnerabilities-in-microsoft-windows-tcpip-stack/