CVE-2025-21240
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21240 is a Remote Code Execution vulnerability affecting the Windows Telephony Service. Published on 2025-01-14, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is linked to CWE-122, with additional NVD-CWE-noinfo classification.
The vulnerability enables remote exploitation over the network with low attack complexity and no required privileges, though it demands user interaction. A successful attack grants an unauthenticated attacker the ability to execute arbitrary code, resulting in high impacts to confidentiality, integrity, and availability.
Microsoft's Security Response Center provides detailed advisory information, including patches and mitigation guidance, at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21240.
Details
- CWE(s)