CVE-2025-21409
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21409 is a Remote Code Execution vulnerability in the Windows Telephony Service. Published on 2025-01-14, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-122, indicating a heap-based buffer overflow with insufficient additional details from NVD-CWE.
The vulnerability can be exploited by a remote unauthenticated attacker over the network with low attack complexity, though it requires user interaction such as clicking a malicious link or file. Successful exploitation enables the attacker to achieve high impacts on confidentiality, integrity, and availability, allowing arbitrary code execution on the targeted Windows system.
Microsoft's update guide provides details on mitigation, available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21409.
Details
- CWE(s)