Microsoft Windows 10
cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*
A heap-based buffer overflow vulnerability has been identified in the Windows Telephony Service. This vulnerability allows an unauthorized attacker to execute code remotely over a network. The issue arises from the way the Telephony Service handles certain data, potentially leading to arbitrary code execution on the affected system.
Exploitation of this vulnerability could lead to remote code execution on the affected system.
Security updates for this vulnerability are available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base article KB5055547 for Windows 10 (both x64-based and 32-bit systems), KB5055523 for Windows Server 2025, and KB5055528 for Windows 11 Version 23H2 (x64-based systems).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.