Published: 2020-10-15. Last Updated: 2020-10-15 18:53:05 UTC by Johannes Ullrich (Version: 1) Highlights Do not disable IPv6 entirely unless you want to break Windows in interesting ways. This can only be exploited from the local subnet. But it may lead to remote code execution / BSOD PoC exploit is easy, but actual RCE is hard. Patch For more details, see also the YouTube video I just published:
![InfoSec Handlers Diary Blog - CVE-2020-16898: Windows ICMPv6 Router Advertisement RRDNS Option Remote Code Execution Vulnerability](https://cdn-ak-scissors.b.st-hatena.com/image/square/514e26609172e4ed9ccee8eb62d075a537f1fef0/height=288;version=1;width=512/https%3A%2F%2Ffanyv88.com%3A443%2Fhttps%2Fisc.sans.edu%2Fdiaryimages%2Fimages%2FScreen%2520Shot%25202020-10-15%2520at%25201_45_06%2520PM.png)