8

CVE-2026-20931

Windows Telephony Service Elevation of Privilege Vulnerability

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1607 HwPlatform x64 Version < 10.0.14393.8783
Microsoft ≫ Windows 10 1607 HwPlatform x86 Version < 10.0.14393.8783
Microsoft ≫ Windows 10 1809 HwPlatform x64 Version < 10.0.17763.8276
Microsoft ≫ Windows 10 1809 HwPlatform x86 Version < 10.0.17763.8276
Microsoft ≫ Windows 10 21h2 Version < 10.0.19044.6809
Microsoft ≫ Windows 10 22h2 Version < 10.0.19045.6809
Microsoft ≫ Windows 11 23h2 Version < 10.0.22631.6491
Microsoft ≫ Windows 11 24h2 Version < 10.0.26100.7623
Microsoft ≫ Windows 11 25h2 Version < 10.0.26200.7623
Microsoft ≫ Windows Server 2008 Version - Update sp2 HwPlatform x64
Microsoft ≫ Windows Server 2008 Version - Update sp2 HwPlatform x86
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Server 2016 Version < 10.0.14393.8783
Microsoft ≫ Windows Server 2019 Version < 10.0.17763.8276
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.4648
Microsoft ≫ Windows Server 2022 23h2 Version < 10.0.25398.2092
Microsoft ≫ Windows Server 2025 Version < 10.0.26100.32230
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.79% 0.529
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-73 External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.

https://www.vicarius.io/vsociety/posts/cve-2026-20931-detection-script-elevation-of-privilege-vulnerability-in-windows-telephony-service
https://www.vicarius.io/vsociety/posts/cve-2026-20931-mitigation-script-elevation-of-privilege-vulnerability-in-windows-telephony-service
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20931
Vendor Advisory