CVE-2024-26230 — Windows Telephony Server Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5036925 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 5036925 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5036899 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5036899 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5036896 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 5036896 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5036896 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5036892 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5036892 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5036892 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5036892 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5036892 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5036892 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5036894 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5036894 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5036893 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5036893 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5036893 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5036893 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5036932 (Monthly Rollup) 5036950 (Security Only) Important Elevation of Privilege 5035920 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22618 Yes 5036932 5036950 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5036932 (Monthly Rollup) 5036950 (Security Only) Important Elevation of Privilege 5035920 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22618 Yes 5036932 5036950 Windows Server 2008 for x64-based Systems Service Pack 2 5036932 (Monthly Rollup) 5036950 (Security Only) Important Elevation of Privilege 5035920 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22618 Yes 5036932 5036950 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5036932 (Monthly Rollup) 5036950 (Security Only) Important Elevation of Privilege 5035920 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22618 Yes 5036932 5036950 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5036967 (Monthly Rollup) 5036922 (Security Only) Important Elevation of Privilege 5035888 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27067 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5036967 (Monthly Rollup) 5036922 (Security Only) Important Elevation of Privilege 5035888 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27067 Yes None Windows Server 2012 | 5036969 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5036969 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5036960 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5036960 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5036899 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5036899 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5036896 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5036896 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 | 5036909 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 (Server Core installation) | 5036909 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022, 23H2 Edition (Server Core installation) | 5036910 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5036925 |
Security Update | Yes |
5036899 |
Security Update | Yes |
5036896 |
Security Update | Yes |
5036892 |
Security Update | Yes |
5036894 |
Security Update | Yes |
5036893 |
Security Update | Yes |
5036969 |
Monthly Rollup | Yes |
5036960 |
Monthly Rollup | Yes |
5036909 |
Security Update | Yes |
5036910 |
Security Update | Yes |
Patch Diff
Use-after-free in Windows Telephony Service (tapisrv.dll). GetUIDllName creates a GOLD dialog object. FreeDialogInstance frees this object without invalidating cross-context pointers. Later TUISPIDLLCallback triggers a virtual function call on the dangling GOLD pointer, leading to arbitrary code execution. Reachable via local RPC to ncalrpc:[tapsrvlpc].
| Function | Address | Change | Note |
|---|---|---|---|
GetUIDllName |
|
modified | Added proper reference counting for GOLD dialog objects |
FreeDialogInstance |
|
modified | Added NULLing of cross-context pointers before freeing GOLD object |
TUISPIDLLCallback |
|
modified | Added validation that GOLD pointer is still valid before virtual function call |
Attack Path
Use-after-free on a Telephony dialog object - freed without invalidating the cross-context pointers that still reference it
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
2 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| Wa1nut4/CVE-2024-26230 | 23 | 2024-08-28 | LPE of CVE-2024-26230 |
| kiwids0220/CVE-2024-26230 | 4 | 2024-04-11 |
Detection Rules
Acknowledgments
None