CVE-2025-21223
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21223 is a Remote Code Execution vulnerability in the Windows Telephony Service, stemming from CWE-122 (Heap-based Buffer Overflow) with additional details classified as NVD-CWE-noinfo. Published on 2025-01-14T18:15:33.947, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant impact across confidentiality, integrity, and availability.
The vulnerability can be exploited remotely over the network by an unauthenticated attacker with no privileges required, though it demands user interaction to succeed. Successful exploitation enables arbitrary code execution on the target system with the privileges of the affected service, potentially leading to full system compromise given the high impact ratings.
Mitigation details are available in the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21223.
Details
- CWE(s)