CVE-2026-20931
8.0 HIGHExternal control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent n...
Published: 2026-01-13 · Last updated: 2026-05-26
Severity and scoring
- CVSS
- 8.0 HIGH
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-73
Affected products
| Vendor | Product |
|---|---|
| microsoft | windows_10_1607, windows_10_1809, windows_10_21h2 |
Description
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-20931
- [Vendor advisory]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20931
- [Other]https://www.vicarius.io/vsociety/posts/cve-2026-20931-detection-script-elevation-of-privilege-vulnerability-in-windows-telephony-service
- [Other]https://www.vicarius.io/vsociety/posts/cve-2026-20931-mitigation-script-elevation-of-privilege-vulnerability-in-windows-telephony-service
Related CVEs
Same vendor
- CVE-2026-50512 — Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privilege... (7.8 HIGH)
- CVE-2026-50511 — Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privilege... (7.8 HIGH)
- CVE-2026-50507 — Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack (6.8 MEDIUM)
- CVE-2026-49161 — Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally (7.8 HIGH)
- CVE-2026-49160 — Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network (7.5 HIGH)
Same CWE
- CVE-2026-10303 — In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 be... (7.4 HIGH)
- CVE-2026-39006 — An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component (9.8 CRITICAL)
- CVE-2026-34030 — The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code when a new branch i...
- CVE-2026-11527 — Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument... (8.6 HIGH)
- CVE-2026-11526 — GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle (9.8 CRITICAL)