CVE-2025-21233
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21233 is a Remote Code Execution vulnerability affecting the Windows Telephony Service in Microsoft Windows operating systems. Published on 2025-01-14, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is linked to CWE-122, with additional NVD-CWE-noinfo classification.
The vulnerability can be exploited by a remote unauthenticated attacker over the network with low attack complexity, though it requires user interaction such as clicking a malicious link or file. Successful exploitation enables the attacker to achieve high-impact effects, including unauthorized access to confidential data, modification of system integrity, and disruption of availability through arbitrary code execution, typically in the context of the affected service.
Microsoft has published an update guide addressing this vulnerability at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21233, which provides details on available patches and recommended mitigations for security practitioners.
Details
- CWE(s)