Executive brief
Windows Fax Service is a built-in Windows component that handles faxing and print-to-fax functionality. An authorized user with local access can trigger a heap-based buffer overflow to gain elevated system privileges, potentially allowing them to take full control of the affected computer and access or modify sensitive data.
Technical details
A heap-based buffer overflow exists in Windows Fax Service that can be exploited by an authenticated local attacker to achieve privilege escalation. The vulnerability requires local access and user-level authorization to trigger. A successful exploit allows an attacker to execute arbitrary code with SYSTEM privileges, effectively gaining full control over the compromised system. Patches from Microsoft should be applied to all affected Windows versions to remediate this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed