Impact
A use after free flaw in the Windows Telephony Service allows an authorized local user to run code with elevated privileges. This vulnerability is classified as a memory‑corruption problem (CWE‑416) and could let a low‑privileged process obtain system‑level rights, enabling full control over the affected system.
Affected Systems
The flaw affects Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and several Windows Server releases including 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both full and Server Core editions).
Risk and Exploitability
With a CVSS score of 7, the vulnerability presents a moderate to high risk. The attack requires local authorization – an application or user already authenticated on the machine. EPSS data is unavailable, and the flaw is not listed in CISA KEV, indicating no confirmed widespread exploitation yet. Nonetheless, the potential for local privilege escalation makes it a significant threat to affected systems.
OpenCVE Enrichment