CVE-2026-62732
Windows Telephony Service Elevation of Privilege Vulnerability
Description
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowThis is a Windows local security hole in the Telephony Service that lets a low-privileged attacker take full control of the computer—if you have that service on and someone can already run low-level code on your machine, you should act quickly.
CVE-2026-62732 is a Windows Telephony Service memory flaw (CWE-122) that enables local elevation of privilege by allowing a low-privileged attacker to trigger a bug without needing user interaction; affected systems include Windows versions where the Telephony Service is installed.
What to do now
- Check whether your Windows machine has the Telephony Service installed/enabled (Telephony/phone-related service components are present).
- Identify your exact Windows version and build number.
- Update using Microsoft’s fix for CVE-2026-62732 (install the security update from the MSRC update guide linked below) so you reach the fixed build for your version:
- Windows 10: 10.0.14393.9418 OR 10.0.17763.9121 OR 10.0.19044.7663 OR 10.0.19045.7663
- Windows 11: 10.0.22631.7517 OR 10.0.26100.9168 OR 10.0.26200.9168 OR 10.0.28000.2704
- Windows Server 2012: 6.2.9200.26280
- Windows Server 2012 R2: 6.3.9600.23338
- Windows Server 2016: 10.0.14393.9418
- Windows Server 2019: 10.0.17763.9121
- If you cannot patch immediately, remove/disable the Telephony Service (or the phone/telephony component) on machines that do not require it, and restrict local low-privilege access as much as possible until updates are applied.
- After patching, verify the Windows update status and re-check that your build matches one of the fixed versions above.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62732 and every CVE in our database. Create a free account — no credit card required.
Create Free Account