Vulnerability record · CVE-2010-0241 · published 10 February 2010
CVE-2010-0241: Windows IPv6 ICMPv6 Route Information packet bounds checking flaw
Microsoft · Windows Server 2008
The TCP/IP stack in Windows Vista (Gold, SP1, SP2) and Windows Server 2008 (Gold, SP2) fails to properly bounds-check ICMPv6 Route Information packets when IPv6 is enabled. A remote, unauthenticated attacker can send crafted packets to trigger memory corruption and execute arbitrary code. Because the flaw is in the kernel network stack, successful exploitation yields full system control.
Description
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Route Information Vulnerability."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10.0 with remote, unauthenticated code execution in the Windows kernel and a high EPSS percentile make this a top remediation priority despite the absence of KEV listing.
What it is
The TCP/IP stack in Windows Vista (Gold, SP1, SP2) and Windows Server 2008 (Gold, SP2) fails to properly bounds-check ICMPv6 Route Information packets when IPv6 is enabled. A remote, unauthenticated attacker can send crafted packets to trigger memory corruption and execute arbitrary code. Because the flaw is in the kernel network stack, successful exploitation yields full system control.
Impact
An attacker gains remote code execution with complete confidentiality, integrity, and availability impact, effectively taking over the affected host. No privileges or user interaction are required beyond the target having IPv6 enabled and reachable.
Attack surface
Reachable over the network via crafted ICMPv6 Route Information packets (AV:N, AC:L, Au:N), requiring no authentication and no user interaction. The only precondition is that IPv6 is enabled on the target, which is the default on the affected Windows versions.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.49, ~98.8th percentile), indicating elevated predicted exploitation likelihood, but the record contains no reference tags confirming public exploit code or in-the-wild use.
What to do
- Apply Microsoft security bulletin MS10-009 immediately on all affected Windows Vista and Server 2008 systems.
- If patching cannot be done at once, disable IPv6 on hosts that do not require it to remove the attack surface.
- Block or filter inbound ICMPv6 Route Information packets at network boundaries and host firewalls where operationally feasible.
- Inventory remaining Vista and Server 2008 systems, since these are end-of-life platforms, and prioritize migration or isolation.
- Monitor vendor and US-CERT advisories for updated guidance on this and related IPv6 stack issues.
Detection
- Monitor for unexpected or malformed ICMPv6 Route Information (type 137) packets reaching hosts, especially from external or untrusted networks.
- Alert on kernel crashes, bugchecks, or unexpected reboots on Vista/Server 2008 systems that could indicate exploitation attempts.
- Use network IDS/IPS signatures for anomalous ICMPv6 traffic and correlate with host logs for suspicious process creation following network activity.
- Audit IPv6 enablement status across the estate to identify exposed hosts that match the vulnerable configuration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0241 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0241), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.