Junglewise Threat Intelligence

CVE-2026-69509: Microsoft Windows Fax Service heap buffer overflow

CVE-2026-69509 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Fax Service is a built-in Windows component that handles faxing and print-to-fax functionality. An authorized user with local access can trigger a heap-based buffer overflow to gain elevated system privileges, potentially allowing them to take full control of the affected computer and access or modify sensitive data.

Technical details

A heap-based buffer overflow exists in Windows Fax Service that can be exploited by an authenticated local attacker to achieve privilege escalation. The vulnerability requires local access and user-level authorization to trigger. A successful exploit allows an attacker to execute arbitrary code with SYSTEM privileges, effectively gaining full control over the compromised system. Patches from Microsoft should be applied to all affected Windows versions to remediate this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats