CVE-2025-21241
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21241 is a Remote Code Execution vulnerability in the Windows Telephony Service. Published on 2025-01-14, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-122 and NVD-CWE-noinfo.
The vulnerability can be exploited by a remote attacker requiring no privileges, though it demands user interaction and features low attack complexity. Successful exploitation enables the attacker to execute arbitrary code, resulting in high impacts to confidentiality, integrity, and availability within the affected system's scope.
Microsoft's update guide provides details on mitigation, available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21241.
Details
- CWE(s)