CVE-2024-43626 — Windows Telephony Service Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5046665 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 5046665 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5046612 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5046612 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5046615 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5046615 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5046613 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5046613 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5046613 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5046613 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5046613 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5046613 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5046633 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5046633 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5046633 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5046633 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5046617 (Security Update) 5046696 (SecurityHotpatchUpdate) Important Elevation of Privilege 5044284 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.2314 10.0.26100.2240 Yes None Windows 11 Version 24H2 for x64-based Systems 5046617 (Security Update) 5046696 (SecurityHotpatchUpdate) Important Elevation of Privilege 5044284 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.2314 10.0.26100.2240 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 5046661 (Monthly Rollup) 5046639 (Security Only) Important Elevation of Privilege 5044320 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22966 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5046661 (Monthly Rollup) 5046639 (Security Only) Important Elevation of Privilege 5044320 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22966 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 5046661 (Monthly Rollup) 5046639 (Security Only) Important Elevation of Privilege 5044320 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22966 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5046661 (Monthly Rollup) 5046639 (Security Only) Important Elevation of Privilege 5044320 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22966 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 5046687 (Monthly Rollup) 5046705 (Security Only) Important Elevation of Privilege 5044356 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27415 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5046687 (Monthly Rollup) 5046705 (Security Only) Important Elevation of Privilege 5044356 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27415 Yes None Windows Server 2012 | 5046697 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5046697 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5046682 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5046682 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5046612 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5046612 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5046615 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5046615 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 5046616 (Security Update) 5046698 (SecurityHotpatchUpdate) Important Elevation of Privilege 5044281 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.2849 10.0.20348.2819 Yes None Windows Server 2022 (Server Core installation) 5046616 (Security Update) 5046698 (SecurityHotpatchUpdate) Important Elevation of Privilege 5044281 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.2849 10.0.20348.2819 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5046618 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5046665 |
Security Update | Yes |
5046612 |
Security Update | Yes |
5046615 |
Security Update | Yes |
5046613 |
Security Update | Yes |
5046633 |
Security Update | Yes |
5046697 |
Monthly Rollup | Yes |
5046682 |
Monthly Rollup | Yes |
5046618 |
Security Update | Yes |
Patch Diff
Heap OOB read/write in tapisrv.dll GetPriorityList due to missing null terminator validation on user-controlled registry value. GetPriorityListTReqCall reads HKCU\...\Telephony\HandOffPriorities\RequestMakeCall and passes unterminated string to _wcsupr() which reads/writes past heap allocation in svchost.exe (SYSTEM). Secondary info leak via lstrlenW() in SetPriorityList writes heap pointers back to registry. Trigger: write REG_BINARY without null terminator + TAPI RPC call (LSetAppPriority, opnum 69).
| Function | Address | Change | Note |
|---|---|---|---|
GetPriorityList |
|
code (null terminator validation added) | Missing null terminator validation on REG_SZ value read via RegQueryValueExW. _wcsupr() reads/writes past heap allocation. Patch replaces RegQueryValueExW with RegGetValueW which auto-appends null terminators for string values. |
SetPriorityList |
|
info leak site | lstrlenW() on unterminated buffer reads past allocation into adjacent heap chunks. RegSetValueExW writes leaked data (including heap pointers) back to registry. Secondary info leak enables ASLR bypass. |
GetPriorityListTReqCall |
|
caller | Opens HKCU\...\Telephony\HandOffPriorities and calls GetPriorityList with RequestMakeCall value name. Entry point from RPC dispatcher via LSetAppPriority (opnum 69). |
Attack Path
Heap OOB read/write in the Telephony Service from an unterminated registry string the caller owns
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.