CVE-2025-21413
published 2025-01-14CVE-2025-21413: Windows Telephony Service Remote Code Execution Vulnerability
PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.09%
61.5th percentile
Windows Telephony Service Remote Code Execution Vulnerability
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20890 | 10.0.10240.20890 |
| microsoft | windows_10_1607 | < 10.0.14393.7699 | 10.0.14393.7699 |
| microsoft | windows_10_1809 | < 10.0.17763.6775 | 10.0.17763.6775 |
| microsoft | windows_10_21h2 | < 10.0.19044.5371 | 10.0.19044.5371 |
| microsoft | windows_10_22h2 | < 10.0.19045.5371 | 10.0.19045.5371 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20890 | 10.0.10240.20890 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7699 | 10.0.14393.7699 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.6775 | 10.0.17763.6775 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5371 | 10.0.19044.5371 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5371 | 10.0.19045.5371 |
| microsoft | windows_11_22h2 | < 10.0.22621.4751 | 10.0.22621.4751 |
| microsoft | windows_11_23h2 | < 10.0.22621.4751 | 10.0.22621.4751 |
| microsoft | windows_11_23h2 | < 10.0.22631.4751 | 10.0.22631.4751 |
| microsoft | windows_11_24h2 | < 10.0.26100.2894 | 10.0.26100.2894 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.4751 | 10.0.22621.4751 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.4751 | 10.0.22631.4751 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.4751 | 10.0.22631.4751 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.2894 | 10.0.26100.2894 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27520 | 6.1.7601.27520 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23070 | 6.0.6003.23070 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25273 | 6.2.9200.25273 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22371 | 6.3.9600.22371 |
| microsoft | windows_server_2016 | < 10.0.14393.7699 | 10.0.14393.7699 |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector requires a user to connect to a malicious server; monitor for unexpected outbound connections from the Windows Telephony Service (tapisrv.dll / svchost hosting TapiSrv) to untrusted hosts. ↗
- ·Exploitation is assessed as 'Less Likely' by Microsoft and has not been publicly disclosed or observed in the wild as of the advisory date. ↗
- ·Customer action is required — patching is necessary; the vulnerability affects the Windows Telephony Service component. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cisa9.8CRITICAL
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h4x8-pvww-m327: Windows Telephony Service Remote Code Execution Vulnerability
ghsa_unreviewed·2025-01-14
CVE-2025-21413 [HIGH] CWE-122 GHSA-h4x8-pvww-m327: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
CISA
Microsoft Outlook Improper Input Validation Vulnerability
cisa·2025-02-06·CVSS 9.8
CVE-2024-21413 [CRITICAL] CWE-20 Microsoft Outlook Improper Input Validation Vulnerability
Vulnerability: Microsoft Outlook Improper Input Validation Vulnerability
Affected: Microsoft Office Outlook
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413 ; https://nvd.nist.gov/vuln/detail/CVE-2024-21413
Remediation Due Date: 2025-02-27
Microsoft
Windows Telephony Service Remote Code Execution Vulnerability
vendor_msrc·2025-01-14·CVSS 8.8
CVE-2025-21413 [HIGH] CWE-122 Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An attacker could exploit this vulnerability by tricking a user into sending a request to a malicious server. This could result in the server returning malicious data that might cause arbitrary code execution on the user's system.
Windows Telephony Service: Windows Telephony Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5050008
Reference: https://support.microsoft.com/help/5050008
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB504
No detection rules found.
No public exploits indexed.
2025-01-14
Published