PT-2025-1167 · Microsoft · Windows Telephony Service+1

Published

2025-01-14

·

Updated

2025-01-24

·

CVE-2025-21245

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Telephony Service (affected versions not specified)
Description The issue is related to a remote code execution problem in the Windows Telephony Service, which can be exploited by remote attackers to execute arbitrary code. This can impact the system. The estimated number of potentially affected devices worldwide is not provided. There is no information about real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Out of bounds Read

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-00448
CVE-2025-21245

Affected Products

Windows
Windows Telephony Service