Microsoft Windows Telephony Service Heap-Based Buffer Overflow Vulnerability Allowing Remote Code Execution

Vulnerability

A heap-based buffer overflow vulnerability has been identified in the Windows Telephony Service. This vulnerability allows an unauthorized attacker to execute code remotely over a network. The issue arises from the way the Telephony Service handles certain data, potentially leading to arbitrary code execution on the affected system.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Remediation

Security updates for this vulnerability are available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base article KB5055547 for Windows 10 (both x64-based and 32-bit systems), KB5055523 for Windows Server 2025, and KB5055528 for Windows 11 Version 23H2 (x64-based systems).

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.