Windows Telephony Service Privilege Escalation Vulnerability by Microsoft
CVE-2026-40382
7.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40382?
A use after free vulnerability in the Windows Telephony Service allows an authorized attacker to manipulate memory and elevate privileges locally. This flaw can enable attackers to execute arbitrary code with elevated rights, potentially compromising system security. Users and administrators are encouraged to apply the patch provided by Microsoft to mitigate this vulnerability and protect their systems from exploitation.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9140
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8755
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7291