CVE-2025-21406
Published: 11 February 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21406 is a remote code execution vulnerability in the Windows Telephony Service. Published on 2025-02-11, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is linked to CWE-416 (Use After Free), with additional NVD-CWE-noinfo classification.
A remote unauthenticated attacker can exploit this vulnerability over the network with low attack complexity, though it requires user interaction. Successful exploitation enables high-impact consequences, including unauthorized access to sensitive data, modification of system integrity, and disruption of availability through arbitrary code execution on the affected Windows system.
Microsoft's update guide provides details on mitigation and patches for CVE-2025-21406 at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21406.
Details
- CWE(s)