
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25188 is a heap-based buffer overflow vulnerability in the Windows Telephony Service that allows an unauthenticated attacker on an adjacent network to elevate privileges without any user interaction. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2012/2012 R2, 2016, 2019, 2022, and 2025. It carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), occurring within the Windows Telephony Service (tapisrv.dll or related components) when processing specially crafted network traffic from an adjacent network segment. An attacker can send malformed telephony protocol messages that trigger an out-of-bounds write on the heap, corrupting memory in a way that enables privilege escalation to SYSTEM level. No authentication, privileges, or user interaction are required, and attack complexity is rated Low, making exploitation straightforward for any attacker with adjacent network access (Microsoft MSRC, Feedly). The vulnerability is also mapped to CAPEC-92 (Forced Integer Overflow), suggesting the heap overflow may be triggered via integer mishandling during buffer size calculations.
Successful exploitation grants the attacker SYSTEM-level privileges on the affected Windows host, resulting in complete compromise of confidentiality, integrity, and availability. An attacker achieving SYSTEM access can install malware, create backdoor accounts, exfiltrate sensitive data, disable security controls, and pivot laterally within the network. The broad scope of affected products — spanning client and server Windows versions from 2012 through 2025 — means enterprise environments with domain-connected infrastructure are at significant risk (Microsoft MSRC, Rapid7).
tapisrv.exe); crash or error events in the Windows Application or System log related to the Telephony Service.svchost.exe hosting the Telephony Service (TapiSrv), particularly shells (cmd.exe, powershell.exe) or network tools (net.exe, whoami.exe) running with SYSTEM privileges.HKLM\SYSTEM\CurrentControlSet\Services\TapiSrv or related telephony registry keys.Microsoft released patches on March 10, 2026, addressing CVE-2026-25188 across all affected platforms. Administrators should apply the following updates immediately: Windows 10 22H2 → 10.0.19045.7058, Windows 10 21H2 → 10.0.19044.7058, Windows 10 1809 → 10.0.17763.8511, Windows 10 1607 → 10.0.14393.8957, Windows 11 23H2 → 10.0.22631.6783, Windows 11 24H2 → 10.0.26100.7979, Windows 11 25H2 → 10.0.26200.7979, Windows 11 26H1 → 10.0.28000.1719, Windows Server 2019 → 10.0.17763.8511, Windows Server 2016 → 10.0.14393.8957, Windows Server 2022 → 10.0.20348.4830, Windows Server 2025 → 10.0.26100.32463, Windows Server 2012 → 6.2.9200.25973, Windows Server 2012 R2 → 6.3.9600.23074. As a temporary workaround where patching is not immediately possible, consider disabling the Windows Telephony Service (TapiSrv) if it is not required, and enforce network segmentation to restrict adjacent network access to sensitive systems (Microsoft MSRC).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security vendors and researchers. Rapid7 and Outpost24 highlighted it among the notable elevation-of-privilege vulnerabilities in their Patch Tuesday analyses (Rapid7, Outpost24). The Zero Day Initiative (ZDI) included it in their March 2026 security update review (ZDI). Sophos and SANS ISC also noted the vulnerability in their Patch Tuesday coverage (Sophos, SANS ISC). Community sentiment emphasized the importance of prompt patching given the no-authentication, adjacent-network attack vector common in enterprise domain environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."