CVE-2025-21282
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-21282 is a remote code execution vulnerability affecting the Windows Telephony Service. Successful exploitation allows an attacker to execute arbitrary code on the targeted system by sending a specially crafted RTP (Real-time Transport Protocol) packet to a vulnerable telephony application. This vulnerability poses a significant risk to organizations that rely on the Windows Telephony Service, particularly those with telecommunication infrastructure. It is recommended that affected systems be updated with the latest Microsoft patches to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
Affected Vendors
- Microsoft