Researchers detailed CVE-2024-26230, an elevation-of-privilege flaw in the Microsoft Windows Telephony Service (TapiSrv) caused by a use-after-free in tapisrv.dll. The bug can be exploited by shaping heap allocations with user-controlled registry data under Telephony\HandoffPriorities, reclaiming freed memory with a fake object, and triggering TUISPIDLLCallback to gain code execution inside the service process. The reported exploit path yields execution as NT AUTHORITY\Network Service and can then be chained with PrintSpoofer to reach SYSTEM because the service token carries SeImpersonatePrivilege.
The research also highlighted CVE-2024-43626, a related Telephony Service issue in GetPriorityList and SetPriorityList tied to improper handling of non-null-terminated registry strings, which can lead to out-of-bounds reads, writes, and information leakage. Microsoft reportedly addressed CVE-2024-43626 in the November 12, 2024 security updates by explicitly null-terminating the string and adding an integer overflow check on cbData. Recommended defenses include applying Microsoft patches, restricting normal users from starting the Telephony service, and monitoring for unexpected Telephony service crashes.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
STAR Labs published a detailed write-up of CVE-2024-26230, describing a use-after-free in the Windows Telephony Service that can be exploited for elevation of privilege. The analysis showed how attacker-controlled Telephony registry data could shape heap allocations, achieve code execution as Network Service, and potentially escalate to SYSTEM via PrintSpoofer.
Microsoft fixed the related Windows Telephony Service flaw CVE-2024-43626 in its November 12, 2024 security updates. The patch explicitly null-terminated the affected string handling and added an integer overflow check on cbData.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.