CVE-2025-21205
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-21205 is a critical heap-based buffer overflow vulnerability affecting Windows Telephony Service. An attacker, without authorization, can exploit this issue over a network, leading to arbitrary code execution. This vulnerability poses a significant risk as the Windows Telephony Service runs with high privileges, making successful exploitation potentially devastating. The attacker could gain full control of the affected system, installing malware, stealing sensitive data, or launching further attacks. Organizations must prioritize patching to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft