CVE-2026-25188
Published: 10 March 2026
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
CVE-2026-25188 is a heap-based buffer overflow vulnerability, classified under CWE-122, affecting the Windows Telephony Service. Published on 2026-03-10T18:18:35.780, it carries a CVSS v3.1 base score of 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant impact.
An unauthorized attacker positioned on an adjacent network can exploit this vulnerability with low attack complexity, requiring no privileges or user interaction. Exploitation enables privilege escalation, granting the attacker high levels of access to confidentiality, integrity, and availability of the affected system.
The Microsoft Security Response Center (MSRC) has published an update guide detailing patches and mitigation measures at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25188.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Heap-based buffer overflow in Windows Telephony Service exploitable by unauthorized adjacent network attacker for privilege escalation, directly enabling T1068 (Exploitation for Privilege Escalation).