Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
Windows Telephony Service: Unprivileged Network Access via Overflow
CVE-2026-25188
Summary
An attacker on the same network as your Windows system can potentially take control of the system by exploiting a weakness in the Windows Telephony Service. This could allow them to access sensitive information or disrupt system operations. Apply Windows updates to patch this vulnerability and ensure your network is secure.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| microsoft | windows_10_1607 | <= 10.0.14393.8957 | – |
| microsoft | windows_10_1607 | <= 10.0.14393.8957 | – |
| microsoft | windows_10_1809 | <= 10.0.17763.8511 | – |
| microsoft | windows_10_1809 | <= 10.0.17763.8511 | – |
| microsoft | windows_10_21h2 | <= 10.0.19044.7058 | – |
| microsoft | windows_10_21h2 | <= 10.0.19044.7058 | – |
| microsoft | windows_10_21h2 | <= 10.0.19044.7058 | – |
| microsoft | windows_10_22h2 | <= 10.0.19045.7058 | – |
| microsoft | windows_10_22h2 | <= 10.0.19045.7058 | – |
| microsoft | windows_10_22h2 | <= 10.0.19045.7058 | – |
| microsoft | windows_11_23h2 | <= 10.0.22631.6783 | – |
| microsoft | windows_11_23h2 | <= 10.0.22631.6783 | – |
| microsoft | windows_11_24h2 | <= 10.0.26100.7979 | – |
| microsoft | windows_11_24h2 | <= 10.0.26100.7979 | – |
| microsoft | windows_11_25h2 | <= 10.0.26200.7979 | – |
| microsoft | windows_11_25h2 | <= 10.0.26200.7979 | – |
| microsoft | windows_11_26h1 | <= 10.0.28000.1719 | – |
| microsoft | windows_11_26h1 | <= 10.0.28000.1719 | – |
| microsoft | windows_server_2012 | All versions | – |
| microsoft | windows_server_2012 | r2 | – |
| microsoft | windows_server_2016 | <= 10.0.14393.8957 | – |
| microsoft | windows_server_2019 | <= 10.0.17763.8511 | – |
| microsoft | windows_server_2022 | <= 10.0.20348.4830 | – |
| microsoft | windows_server_2022_23h2 | <= 10.0.25398.2207 | – |
| microsoft | windows_server_2025 | <= 10.0.26100.32463 | – |
Original title
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.
Original description
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.
nvd CVSS3.1
8.8
Vulnerability type
CWE-122
Heap-based Buffer Overflow
Published: 10 Mar 2026 · Updated: 14 Mar 2026 · First seen: 11 Mar 2026