CVE-2025-21221 Windows Telephony Service Remote Code Execution Vulnerability
Published April 8, 2025
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Published April 8, 2025
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Published April 8, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published April 8, 2025
Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
Published April 8, 2025
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Published April 8, 2025
External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.
Published April 8, 2025
Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
Published April 8, 2025
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Published April 8, 2025
Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
Published April 8, 2025
Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Published April 8, 2025
Access of resource using incompatible type (‘type confusion’) in Microsoft Office allows an unauthorized attacker to execute code locally.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.