Important CVSS 8.8 EPSS 0.00929 🔬 Patch diffed 2024-10 archive

Executive Summary

None

Overview

8.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Remote Code Execution
Released Oct 8 2024
Last Updated Oct 8 2024
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00929 — 0.5747 percentile
NVD CVSS 8.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
Required
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 7.7

EPSS Score

0.00929
probability of exploitation in the next 30 days
0.5747 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

31 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5044286 (Security Update) Important Remote Code Execution Yes
Windows 10 for x64-based Systems 5044286 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1607 for 32-bit Systems 5044293 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1607 for x64-based Systems 5044293 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1809 for 32-bit Systems 5044277 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1809 for x64-based Systems 5044277 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H2 for 32-bit Systems 5044273 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H2 for ARM64-based Systems 5044273 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H2 for x64-based Systems 5044273 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 22H2 for 32-bit Systems 5044273 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 22H2 for ARM64-based Systems 5044273 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 22H2 for x64-based Systems 5044273 (Security Update) Important Remote Code Execution Yes
Windows 11 version 21H2 for ARM64-based Systems 5044280 (Security Update) Important Remote Code Execution Yes
Windows 11 version 21H2 for x64-based Systems 5044280 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 22H2 for ARM64-based Systems 5044285 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 22H2 for x64-based Systems 5044285 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 23H2 for ARM64-based Systems 5044285 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 23H2 for x64-based Systems 5044285 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 24H2 for ARM64-based Systems 5044284 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 24H2 for x64-based Systems 5044284 (Security Update) Important Remote Code Execution Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 5044320 (Monthly Rollup) 5044306 (Security Only) Important Remote Code Execution 5043135 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22918 Yes 5044320 5044306 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5044320 (Monthly Rollup) 5044306 (Security Only) Important Remote Code Execution 5043135 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22918 Yes 5044320 5044306 Windows Server 2008 for x64-based Systems Service Pack 2 5044320 (Monthly Rollup) 5044306 (Security Only) Important Remote Code Execution 5043135 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22918 Yes 5044320 5044306 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5044320 (Monthly Rollup) 5044306 (Security Only) Important Remote Code Execution 5043135 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22918 Yes 5044320 5044306 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5044356 (Monthly Rollup) 5044321 (Security Only) Important Remote Code Execution 5043129 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27366 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5044356 (Monthly Rollup) 5044321 (Security Only) Important Remote Code Execution 5043129 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27366 Yes None Windows Server 2012 5044342 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 (Server Core installation) 5044342 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 R2 5044343 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 R2 (Server Core installation) 5044343 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2016 5044293 (Security Update) Important Remote Code Execution Yes
Windows Server 2016 (Server Core installation) 5044293 (Security Update) Important Remote Code Execution Yes
Windows Server 2019 5044277 (Security Update) Important Remote Code Execution Yes
Windows Server 2019 (Server Core installation) 5044277 (Security Update) Important Remote Code Execution Yes
Windows Server 2022 5044281 (Security Update) Important Remote Code Execution Yes
Windows Server 2022 (Server Core installation) 5044281 (Security Update) Important Remote Code Execution Yes
Windows Server 2022, 23H2 Edition (Server Core installation) 5044288 (Security Update) Important Remote Code Execution Yes

Patches

11 patches
Article Type Restart
5044286 Security Update Yes
5044293 Security Update Yes
5044277 Security Update Yes
5044273 Security Update Yes
5044280 Security Update Yes
5044285 Security Update Yes
5044284 Security Update Yes
5044342 Monthly Rollup Yes
5044343 Monthly Rollup Yes
5044281 Security Update Yes
5044288 Security Update Yes

Patch Diff

ghidriff · tapi32.dll (KB5044273)

Integer overflow -> heap-based buffer overflow (CWE-190 -> CWE-122) in the Windows Telephony client library tapi32.dll, RCE over the Telephony Server RPC interface (an admin user's client connecting to a malicious server, per MSRC FAQ). GrowBuf grows a client buffer by repeatedly doubling its size until it holds curBufSize + addBufSize (addBufSize = the a4 arg, server-influenced), then ClientAllocReal(bufSize) + memcpy. The doubling `bufSize *= 2` has no overflow guard, so a large required size wraps the 32-bit bufSize to a small value; ClientAllocReal allocates a much smaller buffer than intended and the memcpy overflows the heap. IN-HOUSE ghidriff of tapi32.dll 10.0.19041.3636 -> .5007 (Oct 8 2024) confirms the fix: GrowBuf adds an overflow check on the doubling loop (`bVar4 = uVar3 <= uVar3 * 2` - the next double must not wrap) before ClientAllocReal, gated behind CFR flag Feature_1481456953 (GrowBuf gains a Feature_1481456953__private_IsEnabledDeviceUsage call). Credit: Anonymous.

Pre-patch version 10.0.19041.3636 Download
Post-patch version 10.0.19041.5007 Download
Function Address Change Note
GrowBuf code change code (integer-overflow check on size doubling, CFR-gated) Pre: `for (bufSize = 2*curBufSize; bufSize < curBufSize + addBufSize; bufSize *= 2);` then ClientAllocReal(bufSize) + memcpy - the doubling can wrap 32-bit -> undersized alloc -> heap overflow. Post (Feature_1481456953 enabled): adds `uVar3 <= uVar3 * 2` overflow check in the loop and stops instead of allocating a wrapped size. Gains a call to Feature_1481456953__private_IsEnabledDeviceUsage vs pre.
Feature_1481456953 gate added (CFR gate) Controlled Feature Rollout flag gating the overflow-checked GrowBuf path; both branches ship in .5007.
View full diff report View RCA report

Attack Path

A malicious Telephony server drives GrowBuf's size doubling past 32 bits, undersizing the alloc for a heap overflow

Attack path for CVE-2024-43518 A malicious Telephony server drives GrowBuf's size doubling past 32 bits, undersizing the alloc for a heap overflow 01 — ENTRY An admin user's Telephony client connects to a malicious server over the Telephony RPC interface tapi32.dll marshals TAPI calls to the Telephony Server over RPC. Per MSRC, exploitation requires the client to connect to an attacker-controlled server whose responses drive the client's buffer handling. 02 — CONTROLLED INPUT The server returns a response requiring a large buffer (large addBufSize) addBufSize (the a4 argument to GrowBuf) is server-influenced; a large value forces the buffer-grow path. 03 — PATH GrowBuf doubles bufSize until it reaches curBufSize + addBufSize, then allocates and copies `for (bufSize = 2*curBufSize; bufSize < curBufSize + addBufSize; bufSize *= 2);` then ClientAllocReal(bufSize) and memcpy the data in. 04 — MISSING CHECK The bufSize doubling has no overflow guard and wraps 32-bit When the required size is large, `bufSize *= 2` exceeds UINT_MAX and wraps to a small value (CWE-190), so ClientAllocReal allocates far less than needed. 05 — PRIMITIVE memcpy into the undersized heap buffer -> heap overflow -> RCE The large copy overruns the small allocation with attacker-influenced data (CWE-122), giving remote code execution in the client. The Oct 2024 fix adds an overflow check on the doubling, gated behind Feature_1481456953.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Known Exploits

Acknowledgments

Anonymous