CVE-2026-20931: Windows Telephony Service Elevation of Privilege Vulnerability
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
Other sources
Windows Telephony Service Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25868Patch KB5073698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22968Patch KB5073696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23717Patch KB5073700 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.28117Patch KB5073699 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8783Patch KB5073722 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32230Patch KB5073379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2092Patch KB5073450 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6491Patch KB5073455 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8276Patch KB5073723 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4648Patch KB5073457
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20931?
CVE-2026-20931 has been assigned a high severity level due to its potential to allow an attacker to escalate privileges.
How do I fix CVE-2026-20931?
To fix CVE-2026-20931, apply the latest security patches provided by Microsoft for affected Windows products.
Which Windows versions are affected by CVE-2026-20931?
CVE-2026-20931 affects various Windows Server and Windows 10 versions, including Windows Server 2012, 2016, 2019, and 2022.
What is the impact of CVE-2026-20931?
Exploitation of CVE-2026-20931 can lead to unauthorized elevation of privileges over an adjacent network.
Can CVE-2026-20931 be exploited remotely?
Yes, CVE-2026-20931 can potentially be exploited by an authorized user from an adjacent network.