CVE-2025-21201 — Windows Telephony Server Remote Code Execution Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5052040 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 for x64-based Systems | 5052040 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5052006 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5052006 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5052000 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5052000 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5051974 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5051974 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5051974 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5051974 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5051974 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5051974 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5051989 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5051989 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5051989 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5051989 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5051987 (Security Update) 5052105 (SecurityHotpatchUpdate) Important Remote Code Execution 5050009 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3194 10.0.26100.3107 Yes None Windows 11 Version 24H2 for x64-based Systems 5051987 (Security Update) 5052105 (SecurityHotpatchUpdate) Important Remote Code Execution 5050009 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3194 10.0.26100.3107 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 5052038 (Monthly Rollup) 5052072 (Security Only) Important Remote Code Execution 5050063 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23117 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5052038 (Monthly Rollup) 5052072 (Security Only) Important Remote Code Execution 5050063 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23117 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 5052038 (Monthly Rollup) 5052072 (Security Only) Important Remote Code Execution 5050063 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23117 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5052038 (Monthly Rollup) 5052072 (Security Only) Important Remote Code Execution 5050063 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23117 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 5052016 (Monthly Rollup) 5052032 (Security Only) Important Remote Code Execution 5050049 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27566 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5052016 (Monthly Rollup) 5052032 (Security Only) Important Remote Code Execution 5050049 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27566 Yes None Windows Server 2012 | 5052020 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 (Server Core installation) | 5052020 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 | 5052042 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5052042 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 | 5052006 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5052006 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 | 5052000 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5052000 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2022 5051979 (Security Update) 5052106 (SecurityHotpatchUpdate) Important Remote Code Execution 5049983 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3207 10.0.20348.3148 Yes None Windows Server 2022 (Server Core installation) 5051979 (Security Update) 5052106 (SecurityHotpatchUpdate) Important Remote Code Execution 5049983 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3207 10.0.20348.3148 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5051980 (Security Update) |
Important | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5052040 |
Security Update | Yes |
5052006 |
Security Update | Yes |
5052000 |
Security Update | Yes |
5051974 |
Security Update | Yes |
5051989 |
Security Update | Yes |
5052020 |
Monthly Rollup | Yes |
5052042 |
Monthly Rollup | Yes |
5051980 |
Security Update | Yes |
Patch Diff
Double free (CWE-415) in the Windows Telephony Server client-side TAPI Remote Service Provider remotesp.tsp, remote code execution on a client that connects to a malicious telephony server (Important, RCE, AV:N, UI:R, CVSS 8.8). remotesp.tsp issues async requests to a remote telephony server and processes its responses in RemoteDoFunc, which walks the returned per-request records and copies each record's data back into the corresponding client-side outstanding-request buffer selected from an array. PRE: a returned record was applied to its slot WITHOUT verifying it corresponded to that outstanding request, so a crafted server response could route a mismatched/duplicate completion to a request buffer it did not own, reprocessing/re-releasing a buffer whose lifetime had already ended - a double free. Because the client parses attacker-controlled server data over the network, the double free is an RCE primitive on the client. Correct binary identification: tapisrv.dll/tapi32.dll were unchanged (.3037) across Jan->Feb; remotesp.tsp went .2894 (KB5050094) -> .3194 (KB5051987), matching the MSRC fixed build exactly. Self-diff (ghidriff, --no-bsim) of remotesp.tsp 10.0.26100.2894 -> .3194 confirms the fix: RemoteDoFunc, gated behind CFR flag Feature_2332850489, adds an identity check (returned record's leading field must equal the target client buffer's leading field) and returns 0x80000048 on mismatch before the memcpy, so only a record matching its outstanding request is applied. Stated at confirmed-changed level (RemoteDoFunc is a broad refactor; the isolable mechanism is the added record-to-buffer identity validation).
| Function | Address | Change | Note |
|---|---|---|---|
RemoteDoFunc |
code change |
code (adds returned-record identity check before applying to client buffer, CFR-gated) | Pre: server-returned records applied to client request buffers without verifying the record belonged to that buffer -> a crafted/duplicate response could re-release a buffer (double free). Post (Feature_2332850489): if (*returned_record != **client_buf[slot]) return 0x80000048; before the memcpy, so only matching records are applied. |
RemoteSPAttach |
code change |
code (server-init state guard added) | Reworked under Feature_3862983993 with an added guard on gpCurrInitServer state during attach. |
Feature_2332850489 |
gate |
added (CFR gate) | CFR flag gating the returned-record identity check in RemoteDoFunc; the original unchecked handling remains when the flag is disabled. |
Attack Path
A malicious telephony server returns a mismatched async-completion record, driving a double free on the client
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
Anonymous