CVE-2025-21286
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-21286 is a remote code execution vulnerability affecting the Windows Telephony Service. Successful exploitation allows an attacker to execute arbitrary code on the targeted system. This vulnerability resides in the way the service handles specially crafted input data. An attacker could exploit this issue by sending malicious data to a targeted system over the network. Organizations should apply the available Microsoft patch as soon as possible to mitigate this risk. Failure to do so could result in unauthorized remote access and potential data theft or system compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
Affected Vendors
- Microsoft