VYPR
High severity7.5NVD Advisory· Published Oct 16, 2020· Updated Jun 17, 2026

CVE-2020-16899

CVE-2020-16899

Description

A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote Windows computer. The vulnerability would not allow an attacker to execute code or to elevate user rights directly. The update addresses the vulnerability by correcting how the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets.

Affected products

15
  • cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:x86:*range: 10.0.0
  • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*+ 1 more
    • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*range: 10.0.0
    • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*range: 10.0.0
  • cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2016:1909:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2016:2004:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*range: 10.0.0
    • cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.