Executive brief
A security vulnerability exists in the Windows Telephony Service, which manages phone and modem connections on the operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to steal sensitive data, install malicious software, or disrupt business operations.
Technical details
A use-after-free vulnerability (CWE-416) exists within the Windows Telephony Service. The flaw is triggered when the service improperly handles objects in memory, allowing an attacker to execute code after a memory area has been freed. To exploit this, an attacker must first have local access to the system with low-privileged user credentials. Successful exploitation enables the attacker to gain SYSTEM-level privileges, providing full control over the affected host. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory