Windows Telephony Service Remote Code Execution Vulnerability
CVE-2024-43628

8.8HIGH

Key Information:

Summary

The Windows Telephony Service is susceptible to a remote code execution vulnerability, potentially enabling attackers to exploit this weakness to execute arbitrary code on affected systems. This vulnerability requires an attacker to send specially crafted requests to the Telephony Service, which could lead to unauthorized actions being executed on the system. Organizations using vulnerable versions of Windows 10 and Windows Server products must prioritize security updates to mitigate the risks associated with this vulnerability. Proper awareness and preventive measures are essential for protecting sensitive information and maintaining operational integrity.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20826

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.7515

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.6532

References

EPSS Score

0% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.