Impact
A heap‑based buffer overflow exists in the Windows Telephony Service that can be triggered by an authorized local attacker. The flaw allows the attacker to overwrite heap memory and gain elevated privileges on the target system. This vulnerability is classified as CWE‑122, a heap overflow that can compromise access controls. The CVE description specifies local privilege escalation only; no arbitrary code execution capability is asserted in the provided data.
Affected Systems
Microsoft Windows operating systems, including Windows 10 from version 1607 through 22H2, Windows 11 from build 23H2 through 26H1 (both ARM64 and x64), and Windows Server editions from 2012 to 2025. All listed builds possess the Telephony Service component and are therefore susceptible.
Risk and Exploitability
The risk profile is based on a CVSS score of 7.8, indicating a high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local exploitation (inferred): an attacker who has already gained standard user access to the machine can trigger the overflow by interacting with the Telephony Service, which could then elevate their privileges.
OpenCVE Enrichment