Important CVSS 8.8 EPSS 0.01792 🔬 Patch diffed 2025-02 archive

Executive Summary

None

Overview

8.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Remote Code Execution
Released Feb 11 2025
Last Updated Feb 11 2025
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.01792 — 0.76432 percentile
NVD CVSS 8.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
Required
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 7.7

EPSS Score

0.01792
probability of exploitation in the next 30 days
0.76432 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

25 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5052040 (Security Update) Important Remote Code Execution Yes
Windows 10 for x64-based Systems 5052040 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1607 for 32-bit Systems 5052006 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1607 for x64-based Systems 5052006 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1809 for 32-bit Systems 5052000 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1809 for x64-based Systems 5052000 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H2 for 32-bit Systems 5051974 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H2 for ARM64-based Systems 5051974 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H2 for x64-based Systems 5051974 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 22H2 for 32-bit Systems 5051974 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 22H2 for ARM64-based Systems 5051974 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 22H2 for x64-based Systems 5051974 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 22H2 for ARM64-based Systems 5051989 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 22H2 for x64-based Systems 5051989 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 23H2 for ARM64-based Systems 5051989 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 23H2 for x64-based Systems 5051989 (Security Update) Important Remote Code Execution Yes
Windows 11 Version 24H2 for ARM64-based Systems 5051987 (Security Update) 5052105 (SecurityHotpatchUpdate) Important Remote Code Execution 5050009 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3194 10.0.26100.3107 Yes None Windows 11 Version 24H2 for x64-based Systems 5051987 (Security Update) 5052105 (SecurityHotpatchUpdate) Important Remote Code Execution 5050009 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3194 10.0.26100.3107 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 5052038 (Monthly Rollup) 5052072 (Security Only) Important Remote Code Execution 5050063 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23117 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5052038 (Monthly Rollup) 5052072 (Security Only) Important Remote Code Execution 5050063 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23117 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 5052038 (Monthly Rollup) 5052072 (Security Only) Important Remote Code Execution 5050063 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23117 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5052038 (Monthly Rollup) 5052072 (Security Only) Important Remote Code Execution 5050063 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23117 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 5052016 (Monthly Rollup) 5052032 (Security Only) Important Remote Code Execution 5050049 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27566 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5052016 (Monthly Rollup) 5052032 (Security Only) Important Remote Code Execution 5050049 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27566 Yes None Windows Server 2012 5052020 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 (Server Core installation) 5052020 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 R2 5052042 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 R2 (Server Core installation) 5052042 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2016 5052006 (Security Update) Important Remote Code Execution Yes
Windows Server 2016 (Server Core installation) 5052006 (Security Update) Important Remote Code Execution Yes
Windows Server 2019 5052000 (Security Update) Important Remote Code Execution Yes
Windows Server 2019 (Server Core installation) 5052000 (Security Update) Important Remote Code Execution Yes
Windows Server 2022 5051979 (Security Update) 5052106 (SecurityHotpatchUpdate) Important Remote Code Execution 5049983 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3207 10.0.20348.3148 Yes None Windows Server 2022 (Server Core installation) 5051979 (Security Update) 5052106 (SecurityHotpatchUpdate) Important Remote Code Execution 5049983 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3207 10.0.20348.3148 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) 5051980 (Security Update) Important Remote Code Execution Yes

Patches

8 patches
Article Type Restart
5052040 Security Update Yes
5052006 Security Update Yes
5052000 Security Update Yes
5051974 Security Update Yes
5051989 Security Update Yes
5052020 Monthly Rollup Yes
5052042 Monthly Rollup Yes
5051980 Security Update Yes

Patch Diff

ghidriff · remotesp.tsp (KB5051987)

Double free (CWE-415) in the Windows Telephony Server client-side TAPI Remote Service Provider remotesp.tsp, remote code execution on a client that connects to a malicious telephony server (Important, RCE, AV:N, UI:R, CVSS 8.8). remotesp.tsp issues async requests to a remote telephony server and processes its responses in RemoteDoFunc, which walks the returned per-request records and copies each record's data back into the corresponding client-side outstanding-request buffer selected from an array. PRE: a returned record was applied to its slot WITHOUT verifying it corresponded to that outstanding request, so a crafted server response could route a mismatched/duplicate completion to a request buffer it did not own, reprocessing/re-releasing a buffer whose lifetime had already ended - a double free. Because the client parses attacker-controlled server data over the network, the double free is an RCE primitive on the client. Correct binary identification: tapisrv.dll/tapi32.dll were unchanged (.3037) across Jan->Feb; remotesp.tsp went .2894 (KB5050094) -> .3194 (KB5051987), matching the MSRC fixed build exactly. Self-diff (ghidriff, --no-bsim) of remotesp.tsp 10.0.26100.2894 -> .3194 confirms the fix: RemoteDoFunc, gated behind CFR flag Feature_2332850489, adds an identity check (returned record's leading field must equal the target client buffer's leading field) and returns 0x80000048 on mismatch before the memcpy, so only a record matching its outstanding request is applied. Stated at confirmed-changed level (RemoteDoFunc is a broad refactor; the isolable mechanism is the added record-to-buffer identity validation).

Pre-patch version 10.0.26100.2894 Download
Post-patch version 10.0.26100.3194 Download
Function Address Change Note
RemoteDoFunc code change code (adds returned-record identity check before applying to client buffer, CFR-gated) Pre: server-returned records applied to client request buffers without verifying the record belonged to that buffer -> a crafted/duplicate response could re-release a buffer (double free). Post (Feature_2332850489): if (*returned_record != **client_buf[slot]) return 0x80000048; before the memcpy, so only matching records are applied.
RemoteSPAttach code change code (server-init state guard added) Reworked under Feature_3862983993 with an added guard on gpCurrInitServer state during attach.
Feature_2332850489 gate added (CFR gate) CFR flag gating the returned-record identity check in RemoteDoFunc; the original unchecked handling remains when the flag is disabled.
View full diff report View RCA report

Attack Path

A malicious telephony server returns a mismatched async-completion record, driving a double free on the client

Attack path for CVE-2025-21201 A malicious telephony server returns a mismatched async-completion record, driving a double free on the client 01 — ENTRY Client connects to a malicious telephony server remotesp.tsp (TAPI Remote Service Provider) issues async requests and processes the server's response in RemoteDoFunc. AV:N / PR:N / UI:R (user must connect to the server). 02 — CONTROLLED INPUT Server returns a crafted response with mismatched per-request records The response's records reference client-side request slots they do not actually correspond to. 03 — MISSING CHECK Record applied to a buffer it does not own -> double free (CWE-415) Pre-patch RemoteDoFunc applies the record without an identity check, reprocessing/re-releasing a request buffer whose lifetime had already ended. 04 — IMPACT Double free -> code execution on the client The freed-twice heap allocation is reclaimed/reused, giving an attacker-controlled remote server code execution on the connecting client.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules

Acknowledgments

Anonymous