CVE-2025-21205

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 122

Summary

CVE-2025-21205 is a critical heap-based buffer overflow vulnerability affecting Windows Telephony Service. An attacker, without authorization, can exploit this issue over a network, leading to arbitrary code execution. This vulnerability poses a significant risk as the Windows Telephony Service runs with high privileges, making successful exploitation potentially devastating. The attacker could gain full control of the affected system, installing malware, stealing sensitive data, or launching further attacks. Organizations must prioritize patching to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft