CVE-2024-43518 — Windows Telephony Server Remote Code Execution Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5044286 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 for x64-based Systems | 5044286 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5044293 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5044293 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5044277 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5044277 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5044273 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5044273 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5044273 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5044273 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5044273 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5044273 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5044280 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5044280 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5044285 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5044285 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5044285 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5044285 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems | 5044284 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 24H2 for x64-based Systems | 5044284 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5044320 (Monthly Rollup) 5044306 (Security Only) Important Remote Code Execution 5043135 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22918 Yes 5044320 5044306 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5044320 (Monthly Rollup) 5044306 (Security Only) Important Remote Code Execution 5043135 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22918 Yes 5044320 5044306 Windows Server 2008 for x64-based Systems Service Pack 2 5044320 (Monthly Rollup) 5044306 (Security Only) Important Remote Code Execution 5043135 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22918 Yes 5044320 5044306 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5044320 (Monthly Rollup) 5044306 (Security Only) Important Remote Code Execution 5043135 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22918 Yes 5044320 5044306 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5044356 (Monthly Rollup) 5044321 (Security Only) Important Remote Code Execution 5043129 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27366 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5044356 (Monthly Rollup) 5044321 (Security Only) Important Remote Code Execution 5043129 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27366 Yes None Windows Server 2012 | 5044342 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 (Server Core installation) | 5044342 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 | 5044343 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5044343 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 | 5044293 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5044293 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 | 5044277 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5044277 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2022 | 5044281 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2022 (Server Core installation) | 5044281 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2022, 23H2 Edition (Server Core installation) | 5044288 (Security Update) |
Important | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5044286 |
Security Update | Yes |
5044293 |
Security Update | Yes |
5044277 |
Security Update | Yes |
5044273 |
Security Update | Yes |
5044280 |
Security Update | Yes |
5044285 |
Security Update | Yes |
5044284 |
Security Update | Yes |
5044342 |
Monthly Rollup | Yes |
5044343 |
Monthly Rollup | Yes |
5044281 |
Security Update | Yes |
5044288 |
Security Update | Yes |
Patch Diff
Integer overflow -> heap-based buffer overflow (CWE-190 -> CWE-122) in the Windows Telephony client library tapi32.dll, RCE over the Telephony Server RPC interface (an admin user's client connecting to a malicious server, per MSRC FAQ). GrowBuf grows a client buffer by repeatedly doubling its size until it holds curBufSize + addBufSize (addBufSize = the a4 arg, server-influenced), then ClientAllocReal(bufSize) + memcpy. The doubling `bufSize *= 2` has no overflow guard, so a large required size wraps the 32-bit bufSize to a small value; ClientAllocReal allocates a much smaller buffer than intended and the memcpy overflows the heap. IN-HOUSE ghidriff of tapi32.dll 10.0.19041.3636 -> .5007 (Oct 8 2024) confirms the fix: GrowBuf adds an overflow check on the doubling loop (`bVar4 = uVar3 <= uVar3 * 2` - the next double must not wrap) before ClientAllocReal, gated behind CFR flag Feature_1481456953 (GrowBuf gains a Feature_1481456953__private_IsEnabledDeviceUsage call). Credit: Anonymous.
| Function | Address | Change | Note |
|---|---|---|---|
GrowBuf |
code change |
code (integer-overflow check on size doubling, CFR-gated) | Pre: `for (bufSize = 2*curBufSize; bufSize < curBufSize + addBufSize; bufSize *= 2);` then ClientAllocReal(bufSize) + memcpy - the doubling can wrap 32-bit -> undersized alloc -> heap overflow. Post (Feature_1481456953 enabled): adds `uVar3 <= uVar3 * 2` overflow check in the loop and stops instead of allocating a wrapped size. Gains a call to Feature_1481456953__private_IsEnabledDeviceUsage vs pre. |
Feature_1481456953 |
gate |
added (CFR gate) | Controlled Feature Rollout flag gating the overflow-checked GrowBuf path; both branches ship in .5007. |
Attack Path
A malicious Telephony server drives GrowBuf's size doubling past 32 bits, undersizing the alloc for a heap overflow
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Known Exploits
Acknowledgments
Anonymous