Microsoft Windows Telephony Service Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in the Windows Telephony Service. This issue allows an authorized attacker to locally disclose information by accessing memory addresses that should not be available. The vulnerability affects multiple Windows versions, including various releases of Windows Server, Windows 10, and Windows 11.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, specifically local memory addresses.

Remediation

Users can apply the security update for their specific Windows version. Security update KB5094128 is available for Windows Server 2022, KB5094123 for Windows Server 2019, KB5094041 for Windows Server 2012 R2, KB5094042 for Windows Server 2012, KB5094126 for Windows 11, and KB5094127 for Windows 10. These security updates can be downloaded via the Microsoft Update Catalog.

Added: Jun 9, 2026, 7:44 PM
Updated: Jun 9, 2026, 7:44 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.3
remediation
7.7
relevance
9.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.