Skip to content
Skip to content
June 26, 2026
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy

Microsoft News Now

The Home of Microsoft News Today

Primary Menu
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Light/Dark Button
Subscribe

Home - News - Microsoft patches critical zero-click TCP/IP RCE flaw CVE-2024-38063, North Korea’s Lazarus Group exploits zero-day flaw, CVE-2024-38193

  • News

Microsoft patches critical zero-click TCP/IP RCE flaw CVE-2024-38063, North Korea’s Lazarus Group exploits zero-day flaw, CVE-2024-38193

Microsoft has patched two critical security flaws in Windows, a zero-click TCP/IP RCE flaw (CVE-2024-38063) and a zero-day flaw (CVE-2024-38193) exploited by North Korea's Lazarus Group. The zero-click flaw could allow unauthenticated remote code execution attacks on Windows systems with IPv6 enabled, while the zero-day flaw was used by the Lazarus Group to gain system privileges.
Dave W. Shanahan 2 years ago (Last updated: 1 year ago) 2 minutes read
Microsoft August 2024 Patch Tuesday updates; New fixes for 9 zero-days, 6 exploited vulnerabilities, Microsoft patches critical zero-click TCP/IP RCE flaw CVE-2024-38063, North Korea's Lazarus Group exploits zero-day flaw, CVE-2024-38193

Microsoft has patched two critical security flaws in Windows, a zero-click TCP/IP RCE flaw (CVE-2024-38063) and a zero-day flaw (CVE-2024-38193) exploited by North Korea’s Lazarus Group. The zero-click flaw could allow unauthenticated remote code execution attacks on Windows systems with IPv6 enabled, while the zero-day flaw was used by the Lazarus Group to gain system privileges.

CVE-2024-38063 zero-click TCP/IP RCE flaw

The flaw, described as a wormable vulnerability, was patched by Microsoft on August 13, 2024, as part of its monthly security update (KB5041160). The flaw affects all Windows systems with IPv6 enabled and could allow attackers to execute arbitrary code on vulnerable systems without any user interaction.

CVE-2024-38193 zero-day flaw

Microsoft patches critical zero-click TCP/IP RCE flaw CVE-2024-38063, North Korea's Lazarus Group exploits zero-day flaw, CVE-2024-38193

The zero-day flaw, tracked as CVE-2024-38193, was exploited by the Lazarus Group to gain system privileges on Windows systems. The flaw was patched by Microsoft in June 2024, but details of the vulnerability were only recently disclosed. The Lazarus Group is a state-sponsored actor affiliated with North Korea, known for its sophisticated cyberattacks.

Patch Tuesday updates

Microsoft August 2024 Patch Tuesday updates; New fixes for 9 zero-days, 6 exploited vulnerabilities, Microsoft patches critical zero-click TCP/IP RCE flaw CVE-2024-38063, North Korea's Lazarus Group exploits zero-day flaw, CVE-2024-38193

Microsoft has urged users to apply the patches immediately to protect against potential attacks. The company’s swift action in addressing these critical security flaws underscores its commitment to enhancing security against sophisticated threats.

  1. CVE-2024-38063: A zero-click TCP/IP RCE flaw that could allow unauthenticated remote code execution attacks on Windows systems with IPv6 enabled.
  2. CVE-2024-38193: A zero-day flaw exploited by North Korea’s Lazarus Group to gain system privileges on Windows systems.
  3. Patch: Microsoft has patched both flaws as part of its monthly security updates.
  4. Lazarus Group: A state-sponsored actor affiliated with North Korea, known for its sophisticated cyberattacks.

Microsoft patches critical zero-click TCP/IP RCE flaw CVE-2024-38063, North Korea's Lazarus Group exploits zero-day flaw, CVE-2024-38193

The patching of these critical security flaws highlights the ongoing battle between tech giants like Microsoft and state-sponsored actors. It underscores the importance of continuous vigilance and swift action in addressing security vulnerabilities to protect users and maintain the integrity of digital systems.

About The Author

zero-click tcp/ip rce

Dave W. Shanahan

I’m Dave W. Shanahan, a Microsoft enthusiast with a passion for Windows, Xbox, Microsoft 365 Copilot, Azure, and more. I started MSFTNewsNow.com to keep the world updated on Microsoft news. Based in Massachusetts, you can email me at davewshanahan@gmail.com.

See author's posts

Like this:

LikeLoading…

Related


Discover more from Microsoft News Now

Subscribe to get the latest posts sent to your email.

Tags: MicrosoftPatch TuesdaySecurityWindows

Post navigation

Previous: Microsoft announces mandatory multi-factor authentication (MFA/2FA) for more secure Azure sign-ins
Next: Microsoft 365 apps for macOS exposed to library injection attacks

Related Stories

XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs
  • News
  • XBOX and Gaming

Unfortunately Expected: XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs

Dave W. Shanahan 1 day ago 0
XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend
  • News
  • XBOX and Gaming

XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend

Dave W. Shanahan 1 day ago 0
Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI
  • News
  • AI and Copilot

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI

Dave W. Shanahan 3 days ago 0

AccessibilityAmazonAndroidAuthenticationAzureCall of DutyCopilotCybersecurityDeveloperEnterpriseFree Play DaysGamingGenerative AIGitHubGoogleLinkedinMicrosoftMicrosoft 365Microsoft 365 CopilotMicrosoft CopilotMicrosoft EdgeMicrosoft StoreMicrosoft TeamsNext Week on XBOXOpenAIOutlookPatch TuesdayPrivacySecuritySettingsSharePointSurfaceTwitterWindowsWindows 10Windows 11Windows InsiderXBOXXBOX Game PassXBOX Game Pass UltimateXBOX OneXBOX Play AnywhereXBOX Series XXBOX Series X|SXBOX Wire

Useful Links

  • AI and Copilot (249)
  • Azure & Cloud (35)
  • Developers (3)
  • Enterprise (3)
  • How To Guides (98)
  • Microsoft 365/Office (95)
  • Microsoft Announcements (97)
  • News (1,264)
  • Security (78)
  • Surface (47)
  • Windows (166)
  • XBOX and Gaming (414)

You May Have Missed

XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs
  • News
  • XBOX and Gaming

Unfortunately Expected: XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs

Dave W. Shanahan 1 day ago 0
XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend
  • News
  • XBOX and Gaming

XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend

Dave W. Shanahan 1 day ago 0
Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI
  • News
  • AI and Copilot

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI

Dave W. Shanahan 3 days ago 0
Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence
  • News
  • XBOX and Gaming

Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence

Dave W. Shanahan 3 days ago 0
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Copyright © 2026 All rights reserved. ReviewNews by AF themes.

    %d