Impact
The vulnerability is a use‑after‑free flaw in the Windows Telephony Service that enables an attacker with local privileges to execute code at higher privileges. The flaw falls under CWE‑416, which can lead to unauthorized access to protected system resources and compromise the integrity of the operating environment.
Affected Systems
Affected operating system versions include Windows 10 version 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, 2025. The vulnerability is present on both 32‑bit and 64‑bit architectures as indicated by the CPE listings.
Risk and Exploitability
The CVSS score is 7.8, reflecting a high risk of privilege escalation for local attackers. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user with local credentials who can trigger the vulnerable service; no remote entry is implied by the provided information.
OpenCVE Enrichment