CVE-2025-21200
Published: 11 February 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21200 is a Remote Code Execution vulnerability in the Windows Telephony Service. Published on 2025-02-11, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-122 (Heap-based Buffer Overflow) and NVD-CWE-noinfo.
A remote unauthenticated attacker can exploit this vulnerability over the network with low attack complexity, provided they can trick a user into some form of interaction. Successful exploitation enables the attacker to achieve high impacts on confidentiality, integrity, and availability, allowing remote code execution on the affected Windows system.
Microsoft's update guide provides details on mitigations and patches for this vulnerability at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21200.
Details
- CWE(s)