CVE-2025-21407
Published: 11 February 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21407 is a Remote Code Execution vulnerability in the Windows Telephony Service. Published on 2025-02-11, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-122 (Heap-based Buffer Overflow) and NVD-CWE-noinfo.
The vulnerability can be exploited by an unauthenticated remote attacker requiring low attack complexity but user interaction on the target system. Successful exploitation enables the attacker to achieve high impacts across confidentiality, integrity, and availability, allowing remote code execution on affected Windows systems.
Microsoft's Security Response Center has published an update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21407, which provides details on available patches and mitigation recommendations.
Details
- CWE(s)