Impact
Windows Telephony Service contains a use‑after‑free flaw that can be triggered by an authenticated user. When the vulnerability is exploited, the attacker can gain privileges higher than those under which they originally authenticated, potentially allowing them to execute arbitrary code or modify system settings. This flaw is identified as CWE‑416. The primary impact is elevation of local privileges, which can lead to complete system compromise if the attacker achieves administrative level.
Affected Systems
Affected systems are Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1, and the Windows Server family from 2012 (including core), 2012 R2, 2016, 2019, 2022 and 2025. The service is present in both 32‑bit and 64‑bit builds as well as ARM64 where listed.
Risk and Exploitability
The CVSS score of 7 classifies this as high severity. The vulnerability requires local, authorized access; the EPSS score is less than 1 %, indicating a low likelihood of exploitation today, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high CVSS indicates that a successful local exploitation can lead to significant compromise. Detection is likely limited to signs of privilege escalation. The overall risk is considered moderate to high for organizations with unpatched machines or where the Telephony Service is in use.
OpenCVE Enrichment