Impact
The vulnerability is a race condition (CWE-362) in the Windows Telephony Service that also leads to a use‑after‑free (CWE-416). Concurrent executions of the service that share a resource can be manipulated by an attacker with local privileges to cause the improper synchronization to release a freed memory pointer and reallocate it for an attacker‑controlled operation. The result is a local privilege escalation in which the attacker can execute arbitrary code with higher privileges on the same machine.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607 (Anniversary Update), 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and core installations. All of these operating system releases contain the vulnerable Telephony Service component.
Risk and Exploitability
The CVSS score of 7 marks this flaw as high severity, while the EPSS score of under 1 % indicates that large‑scale exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a local, authenticated attacker who can trigger the race condition via the Telephony Service. When successful, the attacker gains administrative privileges and full control over the host machine.
OpenCVE Enrichment