Impact
The vulnerability is a use‑after‑free flaw in the Windows Telephony Service that permits an authorized local attacker to gain elevated privileges. The flaw occurs when the service accesses a freed memory object, which can lead to execution of code with higher privileges on the machine.
Affected Systems
Affected systems include Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 (Server Core), 2012 R2, 2012 R2 (Server Core), 2016, 2016 (ServCore), 2019, 2019 (ServCore), 2022, 2025, and 2025 (ServCore). The vulnerability affects both x86 and x64 architectures and includes ARM64 builds for certain Windows 11 releases.
Risk and Exploitability
The CVSS score of 7.0 indicates a medium to high potential for local privilege escalation. The attack requires local, authorized access and no remote exploitation is described. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported at this time. Nevertheless, due to its impact, precautionary measures are advisable.
OpenCVE Enrichment