CVE-2025-21413
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21413 is a Remote Code Execution vulnerability in the Windows Telephony Service. Published on 2025-01-14, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-122, indicating a heap-based buffer overflow.
An unauthenticated attacker can exploit this vulnerability remotely over the network with low complexity and no required privileges, though user interaction is necessary. Successful exploitation enables arbitrary code execution with high impact on confidentiality, integrity, and availability within the affected system's scope.
Microsoft's update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21413 provides details on patches and mitigation steps.
Details
- CWE(s)