Bad Neighbor is a remote code execution vulnerability in the Windows TCP/IP stack caused by improper handling of ICMPv6 Router Advertisement packets. A remote attacker can trigger the flaw by sending specially crafted ICMPv6 Router Advertisement traffic to a vulnerable Windows system. The issue affects multiple Windows 10 versions and Windows Server 2019. The vulnerability is in network packet processing within the IPv6 stack, allowing memory corruption during handling of malicious Router Advertisement messages and potentially leading to arbitrary code execution on the target system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a proof-of-concept (PoC) exploit for CVE-2020-16898, also known as 'Bad Neighbor', which is a critical vulnerability in the Windows TCP/IP stack affecting IPv6 Router Advertisement packet processing. The main exploit file, 'crash.py', is a Python script that uses the Scapy library to craft and send specially constructed IPv6 Router Advertisement and RDNSS packets to a specified target IPv6 address. The exploit leverages packet fragmentation and malformed options to trigger a stack overflow in the target's network stack, resulting in a Blue Screen of Death (BSOD) on Windows 10 version 2004 systems. The script requires the attacker to know the target's IPv6 address and have network access to it. The repository is structured simply, with a README describing the exploit and a single Python script implementing the attack. No detection or post-exploitation capabilities are present; the exploit is focused solely on causing a denial of service.
This repository provides proof-of-concept (PoC) exploit code for CVE-2020-16898, also known as 'Bad Neighbor', a critical remote code execution/denial of service vulnerability in the Windows TCP/IP stack (specifically in the handling of ICMPv6 Router Advertisement packets). The repository contains several Python scripts (using Scapy) that craft and send malicious IPv6 packets to a target Windows 10 system, causing a Blue Screen of Death (BSOD) by triggering a stack overflow. The main exploit scripts are 'CVE-2020-16898-exp1.py' and 'CVE-2020-16898.py' (and its variants), which require the attacker to know the target's link-local IPv6 address. There is also a PowerShell script ('CVE-2020-16898_Checker.ps1') intended to check if a local system is vulnerable, but it is not an exploit. The repository is structured with clear separation between PoC, exploit, and documentation files, and is focused on demonstrating the vulnerability's impact (system crash) rather than providing a weaponized remote code execution payload.
This repository contains a single Python script (CVE-2020-16898.py) that serves as a proof-of-concept exploit for CVE-2020-16898, a critical vulnerability in the Windows TCP/IP stack (also known as 'Bad Neighbor'). The script uses the Scapy library to craft and send fragmented IPv6 packets with malformed ICMPv6 Router Advertisement and RDNSS options to a specified IPv6 address. The exploit is designed to trigger a Blue Screen of Death (BSOD) on vulnerable Windows systems by exploiting improper handling of these options. The script is a denial-of-service (DoS) exploit and does not provide remote code execution or shell access. The only endpoints present are the hardcoded IPv6 source and destination addresses, which can be modified by the user. The repository is a minimal, single-file PoC with no additional files or documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.