PT-2025-1046 · Microsoft · Windows Telephony Service+1

Published

2025-01-14

·

Updated

2025-01-24

·

CVE-2025-21238

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
The Windows Telephony Service is affected by a remote code execution issue, allowing remote attackers to execute arbitrary code and gain control over the system. This issue can impact many Internet users. The affected software is the Windows Telephony Service, but the specific vulnerable versions are not specified. An exploit for this issue may be available, and more information can be found at https://t.co/JTGshHfTiB. #WindowsTelephonyService #RemoteCodeExecution #WindowsSecurity #TelephonyService #WindowsExploit #RemoteAttack #CodeExecution

Fix

RCE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-00276
CVE-2025-21238

Affected Products

Windows
Windows Telephony Service