Impact
This vulnerability is a heap-based buffer overflow in the Windows Telephony Service, identified as CWE‑122. An attacker who already has local access can trigger the overflow and cause the service to execute code with higher privileges. The flaw allows an escalation of privileges from standard to elevated user rights, which increases the risk of a broader compromise on the affected system. The CVSS score of 7.8 indicates a high overall risk.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
The vulnerability can only be exploited locally by an authorized user. Successful exploitation would raise the process’s privileges, allowing the attacker to perform additional privileged actions such as installing malware, modifying system settings, or further lateral movement in the network. The CVSS score reflects this high impact, while the lack of an EPSS score or KEV listing suggests that, as of now, there is no known publicly documented exploit and the risk is primarily theoretical unless an attacker gains local access. Implementing the official update from Microsoft and limiting access to the Telephony Service is essential.
OpenCVE Enrichment