Executive brief
A security vulnerability exists in the Windows Telephony Service, a component responsible for managing phone and modem connections on Windows computers. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to steal sensitive data, install malicious software, or disrupt business operations.
Technical details
A use-after-free vulnerability (CWE-416) exists within the Windows Telephony Service (TapiSrv). The flaw is triggered when the service improperly handles objects in memory, allowing an attacker to reference memory after it has been freed. To exploit this, an attacker must first have local access to the target system with low-privileged user credentials. Successful exploitation enables the attacker to execute arbitrary code with elevated system privileges, potentially leading to a full compromise of the host. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory