Junglewise Threat Intelligence

CVE-2026-42825: Microsoft Windows Telephony Service use after free privilege escalation

CVE-2026-42825 · Severity: high · CVSS 7 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Telephony Service, a component that manages phone and modem connections on Windows computers. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A use-after-free vulnerability (CWE-416) exists within the Windows Telephony Service (tapisrv). The flaw is triggered when the service improperly handles objects in memory, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must first have local access to the system with low-level privileges. Successful exploitation enables the attacker to execute code with elevated system privileges, potentially leading to a full compromise of the host. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats