CVE-2025-21302
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21302 is a remote code execution vulnerability affecting the Windows Telephony Service. Published on 2025-01-14, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-122 as well as NVD-CWE-noinfo.
The vulnerability can be exploited by an unauthenticated attacker over the network with low attack complexity, though it requires user interaction. Successful exploitation enables high-impact consequences, including unauthorized access to confidential data, modification of system integrity, and disruption of availability through arbitrary code execution.
Microsoft provides mitigation guidance in its Security Response Center update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21302.
Details
- CWE(s)