Information Disclosure Vulnerability in Windows Telephony Service by Microsoft
CVE-2026-42968
5.5MEDIUM
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 9 June 2026
What is CVE-2026-42968?
An information disclosure vulnerability exists in the Windows Telephony Service, which may allow an authorized attacker to read sensitive information locally due to an out-of-bounds read. This can facilitate unauthorized access to confidential data, highlighting the need for prompt updates and security measures.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9234
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8880
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7417