Impact
The flaw is a use‑after‑free in Windows Telephony Service. A process that has permission to use the service can cause the service to dereference memory that has already been freed, which enables the attacker to gain higher privileges on the local system. This type of vulnerability falls under the category of memory corruption leading to privilege escalation. No evidence suggests remote impact or disclosure; the impact is confined to the local system where the user has authorized access to the service.
Affected Systems
Microsoft Windows 10 in versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 in versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations).
Risk and Exploitability
The vulnerability has a CVSS score of 7, indicating a high severity. The EPSS score is not available, so the exact exploitation probability is unknown. It is not listed in CISA's KEV catalog. The likely attack vector is local; an attacker who already has a foothold on the machine and can utilize the Telephony Service can exploit the use‑after‑free to elevate privileges, potentially to SYSTEM. The impact is a compromise of confidentiality, integrity, and availability at the system level.
OpenCVE Enrichment