CVE-2026-20931

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

high 8.0 CVSS 3.1
Published: Jan 13, 2026
Modified: May 26, 2026
Vendor: Microsoft
Product: Windows 10 1607
Versions: r2

Description

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

References

Related CVEs