DC ElementWertSprache
dc.contributor.authorKerutt, Bennet-
dc.contributor.authorKaven, Sascha-
dc.contributor.authorSchwarz, Monina-
dc.contributor.authorLorenz, Bastian-
dc.contributor.authorSkwarek, Volker-
dc.date.accessioned2026-08-20T08:39:06Z-
dc.date.available2026-08-20T08:39:06Z-
dc.date.issued2026-
dc.identifier.issn2190-846Xen_US
dc.identifier.urihttps://hdl.handle.net/20.500.12738/19854-
dc.description.abstractCVE-2024-38063 is a critical zero-click remote code execution (RCE) vulnerability within the Microsoft Windows IPv6 network stack, holding a CVSS score of 9.8. Exploitable by unauthenticated adversaries via specially crafted IPv6 packets. The vulnerability stems from an integer underflow within the fragment reassembly logic, which is triggered by the improper handling of batched packet processing during extension header parsing. This extended abstract presents a comprehensive analysis of the vulnerability's root cause, establishing the quantitative thresholds required for reliable exploitation based on packet coalescing behaviors. Furthermore, an examination of Microsoft's patch implementation reveals an undocumented rollback mechanism utilizing internal feature flags. This mechanism conditionally retained the vulnerable code path for three months post-patch. Corroborated across multiple recent vulnerabilities, this ` "reversible security" paradigm exposes a systematic patching strategy that contradicts official security policies and introduces novel attack surfaces.en
dc.language.isoenen_US
dc.publisherGesellschaft für Informatiken_US
dc.relation.ispartofSIDAR Reportsen_US
dc.subject.ddc004: Informatiken_US
dc.titleReversible security : a case study of CVE-2024-38063 and the implications of patch rollback mechanismsen
dc.typeinProceedingsen_US
dc.relation.conferenceSPRING graduate workshop 2026en_US
dc.description.versionAlternativeRevieweden_US
local.contributorCorporate.editorGesellschaft für Informatik. Fachgruppe Erkennung und Beherrschung von Vorfällen der Informationssicherheit-
local.contributorPerson.editorOhm, Marc-
tuhh.container.endpage34en_US
tuhh.container.startpage32en_US
tuhh.oai.showtrueen_US
tuhh.publication.instituteForschungs- und Transferzentrum CyberSecen_US
tuhh.publication.instituteFakultät Nachhaltige Ingenieurwissenschaftenen_US
tuhh.publisher.urlhttps://fg-sidar.gi.de/fileadmin/FG/SIDAR/Reports/SIDAR-Report-SR-2026-01.pdf#page=32-
tuhh.publisher.urlhttps://fg-sidar.gi.de/fileadmin/FG/SIDAR/Reports/SIDAR-Report-SR-2026-01.pdf-
tuhh.publisher.urlhttps://fg-sidar.gi.de/publikationen/sidar-reports-
tuhh.relation.ispartofseriesProceedings of the 16th graduate workshop of the special interest group Security - Intrusion Detection and Response (SIDAR) of the German Informatics Society (GI), SPRING 2026en_US
tuhh.type.opusInProceedings (Aufsatz / Paper einer Konferenz etc.)-
dc.type.casraiConference Paper-
dc.type.dinicontributionToPeriodical-
dc.type.drivercontributionToPeriodical-
dc.type.statusinfo:eu-repo/semantics/publishedVersionen_US
dcterms.DCMITypeText-
item.tuhhseriesidProceedings of the 16th graduate workshop of the special interest group Security - Intrusion Detection and Response (SIDAR) of the German Informatics Society (GI), SPRING 2026-
item.creatorGNDKerutt, Bennet-
item.creatorGNDKaven, Sascha-
item.creatorGNDSchwarz, Monina-
item.creatorGNDLorenz, Bastian-
item.creatorGNDSkwarek, Volker-
item.creatorOrcidKerutt, Bennet-
item.creatorOrcidKaven, Sascha-
item.creatorOrcidSchwarz, Monina-
item.creatorOrcidLorenz, Bastian-
item.creatorOrcidSkwarek, Volker-
item.seriesrefProceedings of the 16th graduate workshop of the special interest group Security - Intrusion Detection and Response (SIDAR) of the German Informatics Society (GI), SPRING 2026-
item.openairecristypehttp://purl.org/coar/resource_type/c_5794-
item.grantfulltextnone-
item.languageiso639-1en-
item.openairetypeinProceedings-
item.fulltextNo Fulltext-
item.cerifentitytypePublications-
crisitem.author.deptDepartment Wirtschaftsingenieurwesen (ehemalig, aufgelöst 10.2025)-
crisitem.author.deptDepartment Wirtschaftsingenieurwesen (ehemalig, aufgelöst 10.2025)-
crisitem.author.orcid0009-0001-0498-4460-
crisitem.author.orcid0000-0002-7260-6832-
crisitem.author.orcid0000-0001-5065-1029-
crisitem.author.parentorgFakultät Life Sciences (ehemalig, aufgelöst 10.2025)-
crisitem.author.parentorgFakultät Life Sciences (ehemalig, aufgelöst 10.2025)-
Enthalten in den Sammlungen:Publications without full text
Zur Kurzanzeige

Google ScholarTM

Prüfe

HAW Katalog

Prüfe

Volltext ergänzen

Feedback zu diesem Datensatz


Alle Ressourcen in diesem Repository sind urheberrechtlich geschützt.