Junglewise Threat Intelligence

CVE-2026-42912: Microsoft Windows Telephony Service privilege escalation

CVE-2026-42912 · Severity: high · CVSS 7 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Telephony Service, which manages phone and modem connections on Windows computers. An attacker who already has basic access to a system could exploit a timing error to gain full administrative control. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A race condition (CWE-362) exists in the Windows Telephony Service due to improper synchronization when accessing shared resources. An attacker with low-privileged local access can exploit this flaw by carefully timing execution to interfere with service operations. Successful exploitation allows the attacker to elevate privileges to SYSTEM, granting full control over the affected host. The attack requires high complexity as it depends on winning a race condition, but it does not require user interaction. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References