CVE-2025-21248
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21248 is a Remote Code Execution vulnerability in the Windows Telephony Service, published on 2025-01-14. It carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-122 (Heap-based Buffer Overflow) and NVD-CWE-noinfo.
The vulnerability can be exploited remotely over the network by unauthenticated attackers requiring no privileges, though it demands user interaction. Successful exploitation enables arbitrary code execution in the context of the Telephony Service, resulting in high impacts to confidentiality, integrity, and availability.
Microsoft's update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21248 provides details on patches and mitigation recommendations for addressing this issue.
Details
- CWE(s)