CVE-2025-21273
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21273 is a Remote Code Execution vulnerability in the Windows Telephony Service. Published on 2025-01-14, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-122 and NVD-CWE-noinfo.
The vulnerability can be exploited remotely over the network by an unauthenticated attacker with low attack complexity, though it requires user interaction. Successful exploitation enables high-impact effects on confidentiality, integrity, and availability, allowing the attacker to execute arbitrary code on the affected system.
Mitigation details are available in the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21273.
Details
- CWE(s)