CVE-2024-43626Patch(microsoft / windows_10_1507)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Windows Telephony Service Elevation of Privilege Vulnerability

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2008windows_server_2012

2 versions affected across 15 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-11: 2PoC Mentioned / Linked · 2026-02-11: 1Patch / Workaround · 2026-02-11: 2Technical Details · 2026-02-11: 102-11
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • 0patch@0patch
    Patch

    Micropatches released for Windows Telephony Service Elevation of Privilege Vulnerability (CVE-2024-43626) https://blog.0patch.com/2026/02/micropatches-released-for-windows.html https://t.co/gQlJ8d0IMw

    Post summary

    Micro patches have been released to mitigate CVE-2024-43626, an elevation‑of‑privilege flaw in the Windows Telephony Service, providing a vendor remediation.

    17061876
    8.3K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 0patch Ships Micropatch for Windows Telephony Service EoP (CVE-2024-43626) 0patch released an in-memory micropatch for CVE-2024-43626, a Windows Telephony Service privilege-escalation bug caused by non-null-terminated registry data leading to out-of-bounds string uppercasing and potential code execution. The fix is logically aligned with Microsoft’s remediation and prevents the PoC from crashing the service when 0patch is enabled. 🎯 Target: Global/Windows #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://blog.0patch.com/2026/02/micropatches-released-for-windows.html

    Post summary

    0patch has released an in‑memory micropatch for CVE‑2024‑43626, a Windows Telephony Service privilege‑escalation bug caused by out‑of‑bounds string operations, aligning with Microsoft’s remediation and preventing PoC crashes.

    0000080
    191 followersView on X
CPE platform detail28 entries

28 of 28 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_22h2--arm64
OSmicrosoftwindows_11_22h2--x64
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more