Executive brief
A security vulnerability exists in the Windows Telephony Service, which manages phone and modem connections on Windows systems. An authorized user on the same local network could exploit this flaw to gain higher-level system permissions. This could allow an attacker to take full control of an affected computer, potentially leading to data theft or further network compromise.
Technical details
A privilege escalation vulnerability exists in the Windows Telephony Service (tapisrv) due to improper validation of user-supplied file names or paths (CWE-73). An attacker with low-privileged credentials and adjacent network access can exploit this by providing a manipulated path to the service, leading to unauthorized file operations or execution. Successful exploitation allows the attacker to gain SYSTEM-level privileges on the target host. The vulnerability affects a wide range of Windows client and server versions, including Windows 10, 11, and Server 2025. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 up to 10.0.19045.6809
- Microsoft Windows 11 up to 10.0.26200.7623
- Microsoft Windows Server 2022 up to 10.0.20348.4648
- Microsoft Windows Server 2025 up to 10.0.26100.32230
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory: Microsoft released security updates.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20931
- https://www.vicarius.io/vsociety/posts/cve-2026-20931-detection-script-elevation-of-privilege-vulnerability-in-windows-telephony-service
- https://www.vicarius.io/vsociety/posts/cve-2026-20931-mitigation-script-elevation-of-privilege-vulnerability-in-windows-telephony-service