CVE-2026-25188Disclosure(microsoft / windows_10_1607)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-10); latest day: 3
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline6 mentions / 2d
01223Mentions · 2026-03-10: 3Mentions · 2026-03-16: 3Technical Details · 2026-03-10: 2Technical Details · 2026-03-16: 303-1003-16
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Full discourse6 posts
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-25188 | Windows Telephony Service Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-25188 https://t.co/7HddpYQXJ5

    Post summary

    The text announces CVE-2026-25188, an elevation‑of‑privilege flaw in Windows Telephony Service, but offers no details on exploitation or remediation.

    0000044
    2 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25188 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. https://www.cve.org/CVERecord?id=CVE-2026-25188 ----- Traducción: CVE-2026-25188 desbordamiento de búfer basado en he… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-25188, a heap‑based buffer overflow in Windows Telephony Service, and provides a link to its CVE record.

    0000034
    58 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25188 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. https://www.cve.org/CVERecord?id=CVE-2026-25188

    Post summary

    The post announces CVE-2026-25188, describing a heap-based buffer overflow in Windows Telephony Service that permits privilege escalation over an adjacent network.

    00000226
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25188 - High Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. https://www.thehackerwire.com/vulnerability/CVE-2026-25188/ https://t.co/wgROYGtprk

    Post summary

    The post announces CVE-2026-25188 as a heap‑based buffer overflow in Windows Telephony Service that enables privilege escalation, but it provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000038
    133 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25188: HIGH] Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.#cve,CVE-2026-25188,#cybersecurity https://cvefind.com/CVE-2026-25188

    Post summary

    The tweet announces CVE‑2026‑25188, detailing a heap‑based buffer overflow in Windows Telephony Service that can be exploited to elevate privileges, without providing any PoC, exploit, or patch information.

    0000028
    601 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Microsoft Windows (CVE-2026-25188) https://vuldb.com/?id.350027

    Post summary

    A new Windows vulnerability (CVE-2026-25188) has been disclosed with increased severity, but no technical details, exploits, or mitigation steps are mentioned.

    0000070
    2.1K followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more