Microsoft published security advisories for a broad set of remote code execution vulnerabilities affecting Windows components and enterprise services, including Windows Telephony Service, Hyper-V, ReFS, WSUS, Direct Show, the Windows Mobile Broadband Driver, Windows Server Setup and Boot Event Collection, SQL Server Native Client, and .NET. The largest concentration of disclosures involved the Windows Telephony Service, with multiple CVEs including CVE-2024-43620, CVE-2024-43627, CVE-2025-21190, CVE-2025-21240, CVE-2025-21243, CVE-2025-21250, CVE-2025-21266, CVE-2025-21273, CVE-2025-21409, and CVE-2025-21413, indicating sustained patching activity around a single Windows attack surface.
Other disclosed RCE issues expanded the risk to virtualization, storage, update infrastructure, and server environments through CVE-2026-21244 and CVE-2026-21248 in Windows Hyper-V, CVE-2025-62456 in Windows Resilient File System (ReFS), CVE-2025-59287 in Windows Server Update Service (WSUS), CVE-2025-49666 in Windows Server Setup and Boot Event Collection, CVE-2024-49012 in SQL Server Native Client, CVE-2025-21291 in Windows Direct Show, and CVE-2026-24288 in the Windows Mobile Broadband Driver. One referenced case, CVE-2021-34458, showed the potential severity of Microsoft RCE flaws in virtualized environments, with Microsoft describing a Critical Windows Kernel issue that could enable cross-guest interference on systems using SR-IOV-capable hardware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
48 events from the most recent confirmed update back to the earliest known activity.
Microsoft published CVE-2026-24288 as a remote code execution vulnerability in the Windows Mobile Broadband Driver. The disclosure was added to the Security Update Guide in March 2026.
Microsoft disclosed CVE-2026-21248 as another Windows Hyper-V remote code execution vulnerability on the same day as CVE-2026-21244. This represents a separate Hyper-V flaw addressed in February 2026.
Microsoft disclosed CVE-2026-21244, a remote code execution vulnerability affecting Windows Hyper-V, in February 2026. The entry marks a virtualization-related flaw added to the Security Update Guide.
Microsoft published CVE-2025-62456 as a remote code execution vulnerability in Windows Resilient File System (ReFS). The disclosure appeared in the December 2025 Security Update Guide.
Microsoft disclosed CVE-2025-59287, a remote code execution vulnerability in Windows Server Update Service (WSUS), in October 2025. The publication added another server-side RCE issue to the Security Update Guide.
Microsoft disclosed CVE-2025-49683 as a remote code execution vulnerability affecting Microsoft Virtual Hard Disk in its Security Update Guide. The advisory was published as part of the July 2025 security releases.
Microsoft published CVE-2025-49666 as a remote code execution vulnerability affecting Windows Server Setup and Boot Event Collection. The issue was added to the Security Update Guide in July 2025.
Microsoft disclosed CVE-2025-24056 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the March 2025 security releases.
Microsoft disclosed CVE-2025-21200 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the February 2025 security releases.
Microsoft disclosed CVE-2025-21407 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the February 2025 security releases.
Microsoft disclosed CVE-2025-21201 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the February 2025 security releases.
Microsoft disclosed CVE-2025-21406 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The advisory was published as part of the February 2025 security releases.
Microsoft disclosed CVE-2025-21371 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The advisory was published as part of the February 2025 security releases.
Microsoft disclosed CVE-2025-21190, a Windows Telephony Service remote code execution vulnerability, in February 2025. This indicates continued patching of Telephony Service RCE flaws after the January batch.
Microsoft disclosed CVE-2025-21307 as a remote code execution vulnerability in the Windows Reliable Multicast Transport Driver (RMCAST) through its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21303 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21239 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21236 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21233 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21417 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21223 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21305 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21241 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21246 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21252 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21282 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21411 as a Windows Telephony Service remote code execution vulnerability in its January 2025 Security Update Guide. The advisory represents another distinct Telephony Service flaw addressed in that release cycle.
Microsoft published CVE-2025-21413 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The disclosure was part of the January 2025 security updates.
Microsoft disclosed CVE-2025-21409, a Windows Telephony Service remote code execution vulnerability, in January 2025. The advisory marks another distinct Telephony Service RCE issue addressed that month.
Microsoft added CVE-2025-21291 to the Security Update Guide as a remote code execution vulnerability in Windows Direct Show. The disclosure occurred in the January 2025 release cycle.
Microsoft disclosed CVE-2025-21273 as another Windows Telephony Service remote code execution vulnerability. The flaw was listed in the January 2025 Security Update Guide.
Microsoft published CVE-2025-21266, a Windows Telephony Service remote code execution vulnerability, in its January 2025 security updates. Duplicate advisory and vulnerability listings refer to the same disclosure event.
Microsoft disclosed CVE-2025-21244 as a Windows Telephony Service remote code execution vulnerability in its Security Update Guide. The advisory was published as part of the January 2025 Patch Tuesday security releases.
Microsoft disclosed CVE-2025-21250 as a Windows Telephony Service remote code execution vulnerability in the Security Update Guide. The issue was published during the January 2025 Patch Tuesday cycle.
Microsoft disclosed CVE-2025-21243, a Windows Telephony Service remote code execution vulnerability, in its January 2025 security guidance. The entry represents a distinct Telephony Service flaw.
Microsoft published CVE-2025-21240 as a Windows Telephony Service remote code execution vulnerability in the January 2025 Security Update Guide. This was one of several Telephony Service RCE issues disclosed that day.
Microsoft disclosed CVE-2024-43635 as a Windows Telephony Service remote code execution vulnerability through its Security Update Guide. The advisory was published as part of the November 2024 security releases.
Microsoft disclosed CVE-2024-43627, another Windows Telephony Service remote code execution vulnerability, through its Security Update Guide. The publication marks a separate Telephony Service flaw addressed in November 2024.
Microsoft disclosed CVE-2024-43622, a Windows Telephony Service remote code execution vulnerability, through its Security Update Guide. The advisory was published as part of the November 2024 security releases.
Microsoft disclosed CVE-2024-43621, a Windows Telephony Service remote code execution vulnerability, through its Security Update Guide. The advisory was published as part of the November 2024 security releases.
Microsoft disclosed CVE-2024-43620, a remote code execution vulnerability in Windows Telephony Service, in its Security Update Guide. The entry indicates the issue was addressed in the November 2024 release cycle.
Microsoft added CVE-2024-49012 to its Security Update Guide as a remote code execution vulnerability affecting SQL Server Native Client. The advisory was published as part of Microsoft's November 2024 security releases.
Microsoft disclosed CVE-2024-38045 as a remote code execution vulnerability affecting Windows TCP/IP through its Security Update Guide. The advisory was published as part of Microsoft's September 2024 security releases.
Microsoft disclosed CVE-2024-38160 as a remote code execution vulnerability affecting Windows Network Virtualization through its Security Update Guide. The advisory was published as part of Microsoft's August 2024 security releases.
Microsoft disclosed CVE-2024-30077 as a remote code execution vulnerability affecting Windows OLE through its Security Update Guide. The advisory was published as part of Microsoft's June 2024 security releases.
Microsoft disclosed CVE-2023-21740 as a remote code execution vulnerability affecting Windows Media through its Security Update Guide. The advisory was published as part of Microsoft's December 2023 security releases.
Microsoft disclosed CVE-2023-36028, a remote code execution vulnerability in Microsoft Protected Extensible Authentication Protocol (PEAP), through its Security Update Guide. The advisory was published as part of Microsoft's November 2023 security releases.
Microsoft published guidance for CVE-2021-34458, a critical Windows Kernel remote code execution vulnerability affecting systems hosting virtual machines with SR-IOV-capable hardware. The company said the flaw was not publicly disclosed or exploited in the wild at publication time and that a fix was available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.