CVE-2025-24056 — Windows Telephony Service Remote Code Execution Vulnerability
Executive Summary
Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.
Overview
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5053618 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 for x64-based Systems | 5053618 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5053594 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5053594 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5053596 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5053596 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5053602 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5053602 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5053602 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5053602 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5053598 (Security Update) 5053636 (SecurityHotpatchUpdate) Important Remote Code Execution 5051987 5052105 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3476 10.0.26100.3403 Yes None Windows 11 Version 24H2 for x64-based Systems 5053598 (Security Update) 5053636 (SecurityHotpatchUpdate) Important Remote Code Execution 5051987 5052105 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3476 10.0.26100.3403 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 5053888 (Monthly Rollup) 5053995 (Security Only) Important Remote Code Execution 5052038 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5053888 (Monthly Rollup) 5053995 (Security Only) Important Remote Code Execution 5052038 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 5053888 (Monthly Rollup) 5053995 (Security Only) Important Remote Code Execution 5052038 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5053888 (Monthly Rollup) 5053995 (Security Only) Important Remote Code Execution 5052038 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 5053620 (Monthly Rollup) 5053627 (Security Only) Important Remote Code Execution 5052016 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27618 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5053620 (Monthly Rollup) 5053627 (Security Only) Important Remote Code Execution 5052016 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27618 Yes None Windows Server 2012 | 5053886 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 (Server Core installation) | 5053886 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 | 5053887 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5053887 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 | 5053594 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5053594 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 | 5053596 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5053596 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2022 5053603 (Security Update) 5053638 (SecurityHotpatchUpdate) Important Remote Code Execution 5051979 5052106 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3328 10.0.20348.3270 Yes None Windows Server 2022 (Server Core installation) 5053603 (Security Update) 5053638 (SecurityHotpatchUpdate) Important Remote Code Execution 5051979 5052106 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3328 10.0.20348.3270 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5053599 (Security Update) |
Important | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5053618 |
Security Update | Yes |
5053594 |
Security Update | Yes |
5053596 |
Security Update | Yes |
5053606 |
Security Update | Yes |
5053602 |
Security Update | Yes |
5053886 |
Monthly Rollup | Yes |
5053887 |
Monthly Rollup | Yes |
5053599 |
Security Update | Yes |
Patch Diff
Integer overflow leading to a heap-based buffer overflow (CWE-122) in the Windows Telephony Service tapisrv.dll priority-list readers, remote code execution on a client that connects to a malicious telephony server (Important, RCE, AV:N, UI:R, CVSS 8.8). GetPriorityList / GetMediaModesPriorityLists / LSetAppPriority build media-mode/app priority lists by allocating HeapAlloc(ghTapisrvHeap, value_size + 2) and filling it with value_size bytes (RegQueryValueExW), reserving 2 bytes for a wide terminator. PRE (.3037): the value_size <= value_size + 2 overflow check was gated behind Feature_1390216506 and BYPASSED when the flag was disabled, so a size near 0xFFFFFFFF made value_size + 2 wrap to a tiny allocation that was then overrun by the full-size copy - a heap overflow. Because the Telephony Service processes data from the telephony server the client connects to, MSRC classifies this as RCE on the client connecting to a malicious server. Diff of tapisrv.dll 10.0.26100.3037 -> .3323 (Mar 11 2025, KB5053598; vsize 380928 -> 372736, 25 funcs removed) confirms the fix: the fixed build enforces the value_size <= value_size + 2 overflow guard UNCONDITIONALLY (removing the Feature_1390216506 bypass) before the allocation and copy, and bounds the terminator write; LSetAppPriority also gains bounded 0x104/MAX_PATH app-name handling. Stated at confirmed-changed level (broad priority-list rework; the isolable mechanism is the always-enforced allocation overflow guard).
| Function | Address | Change | Note |
|---|---|---|---|
GetPriorityList / GetMediaModesPriorityLists |
code change |
code (priority-list allocation overflow guard made unconditional) | Pre (.3037): HeapAlloc(value_size + 2) guarded by (Feature_1390216506 disabled || value_size <= value_size + 2) - the overflow check was skipped when the flag was off, so a near-UINT_MAX value_size wrapped to a tiny allocation and was overrun. Post (.3323): value_size <= value_size + 2 enforced unconditionally before HeapAlloc and the RegQueryValueExW copy; terminator write bounded. |
LSetAppPriority |
code change |
code (bounded app-name length handling) | Reworked with a 0x104/MAX_PATH-bounded length loop for the application-name string used to set priority. |
Feature_1390216506 |
gate |
gate (bypass removed) | Pre-patch this CFR flag gated the priority-list overflow check (bypassable when disabled); the fixed build enforces the check unconditionally. |
Attack Path
A malicious telephony server supplies an oversized priority-list value; the size+2 allocation overflows and the buffer is overrun
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
Anonymous