Microsoft Windows Server 2012
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*
A heap-based buffer overflow vulnerability has been identified in the Windows Telephony Service. This vulnerability allows an unauthorized attacker to elevate privileges by sending specially crafted malicious traffic to a vulnerable server over an adjacent network. The issue affects several different versions and ranges of Windows, including various editions of Windows Server, Windows 10, and Windows 11.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges on the affected machine.
Users can download the security update for this vulnerability through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5078752, KB5078885, KB5078766, KB5078774, KB5078938, and KB5079473.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.