CVE-2026-25188
vulnerability analysis and mitigation

Overview

CVE-2026-25188 is a heap-based buffer overflow vulnerability in the Windows Telephony Service that allows an unauthenticated attacker on an adjacent network to elevate privileges without any user interaction. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2012/2012 R2, 2016, 2019, 2022, and 2025. It carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), occurring within the Windows Telephony Service (tapisrv.dll or related components) when processing specially crafted network traffic from an adjacent network segment. An attacker can send malformed telephony protocol messages that trigger an out-of-bounds write on the heap, corrupting memory in a way that enables privilege escalation to SYSTEM level. No authentication, privileges, or user interaction are required, and attack complexity is rated Low, making exploitation straightforward for any attacker with adjacent network access (Microsoft MSRC, Feedly). The vulnerability is also mapped to CAPEC-92 (Forced Integer Overflow), suggesting the heap overflow may be triggered via integer mishandling during buffer size calculations.

Impact

Successful exploitation grants the attacker SYSTEM-level privileges on the affected Windows host, resulting in complete compromise of confidentiality, integrity, and availability. An attacker achieving SYSTEM access can install malware, create backdoor accounts, exfiltrate sensitive data, disable security controls, and pivot laterally within the network. The broad scope of affected products — spanning client and server Windows versions from 2012 through 2025 — means enterprise environments with domain-connected infrastructure are at significant risk (Microsoft MSRC, Rapid7).

Exploitation steps

  1. Reconnaissance: Identify Windows hosts on the same network segment (LAN, VLAN, or Wi-Fi) running the Windows Telephony Service (TAPI). Use network scanners such as Nmap to enumerate hosts and identify Windows systems.
  2. Identify vulnerable versions: Confirm target systems are running unpatched versions (e.g., Windows 10 22H2 prior to 10.0.19045.7058, Windows Server 2022 prior to 10.0.20348.4830, etc.) using banner grabbing or OS fingerprinting.
  3. Craft malicious telephony traffic: Develop or adapt a specially crafted network payload targeting the Windows Telephony Service that triggers the heap-based buffer overflow via malformed TAPI protocol messages.
  4. Send exploit payload: Transmit the crafted packet(s) to the target system from the adjacent network without requiring any credentials or user interaction.
  5. Achieve SYSTEM-level privilege escalation: The heap overflow corrupts memory in the Telephony Service process, enabling arbitrary code execution at SYSTEM level, granting full administrative control over the target host.
  6. Post-exploitation: Deploy a backdoor, create a privileged account, or pivot to other systems on the network (Microsoft MSRC, Feedly).

Indicators of compromise

  • Network: Unusual or malformed traffic directed at the Windows Telephony Service port from unexpected adjacent network hosts; anomalous TAPI-related network connections originating from or targeting internal hosts.
  • Logs: Windows Event Log entries showing unexpected privilege escalation events (Event ID 4672 – Special privileges assigned to new logon) associated with the Telephony Service process (tapisrv.exe); crash or error events in the Windows Application or System log related to the Telephony Service.
  • Process: Unexpected child processes spawned by svchost.exe hosting the Telephony Service (TapiSrv), particularly shells (cmd.exe, powershell.exe) or network tools (net.exe, whoami.exe) running with SYSTEM privileges.
  • File System: New or modified executables, scheduled tasks, or services created by the SYSTEM account following Telephony Service activity; presence of unknown DLLs in system directories.
  • Registry: Unexpected modifications to HKLM\SYSTEM\CurrentControlSet\Services\TapiSrv or related telephony registry keys.

Mitigation and workarounds

Microsoft released patches on March 10, 2026, addressing CVE-2026-25188 across all affected platforms. Administrators should apply the following updates immediately: Windows 10 22H2 → 10.0.19045.7058, Windows 10 21H2 → 10.0.19044.7058, Windows 10 1809 → 10.0.17763.8511, Windows 10 1607 → 10.0.14393.8957, Windows 11 23H2 → 10.0.22631.6783, Windows 11 24H2 → 10.0.26100.7979, Windows 11 25H2 → 10.0.26200.7979, Windows 11 26H1 → 10.0.28000.1719, Windows Server 2019 → 10.0.17763.8511, Windows Server 2016 → 10.0.14393.8957, Windows Server 2022 → 10.0.20348.4830, Windows Server 2025 → 10.0.26100.32463, Windows Server 2012 → 6.2.9200.25973, Windows Server 2012 R2 → 6.3.9600.23074. As a temporary workaround where patching is not immediately possible, consider disabling the Windows Telephony Service (TapiSrv) if it is not required, and enforce network segmentation to restrict adjacent network access to sensitive systems (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security vendors and researchers. Rapid7 and Outpost24 highlighted it among the notable elevation-of-privilege vulnerabilities in their Patch Tuesday analyses (Rapid7, Outpost24). The Zero Day Initiative (ZDI) included it in their March 2026 security update review (ZDI). Sophos and SANS ISC also noted the vulnerability in their Patch Tuesday coverage (Sophos, SANS ISC). Community sentiment emphasized the importance of prompt patching given the no-authentication, adjacent-network attack vector common in enterprise domain environments.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management