CVE-2025-21303
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-21303 is a remote code execution vulnerability affecting Microsoft's Windows Telephony Service. Successful exploitation of this weakness allows attackers to execute arbitrary code on vulnerable systems. The vulnerability stems from insufficient input validation in the service, enabling malicious actors to send specially crafted messages that trigger the code execution. This issue poses a significant risk to organizations running unpatched Windows systems and could potentially lead to serious compromise. It is strongly recommended that affected organizations install the available patch as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2008
- Windows Server 2022
Affected Vendors
- Microsoft