Executive brief
Windows Fax Service is a Windows component that handles faxing functionality. A heap-based buffer overflow vulnerability in this service allows an authorized local user to execute arbitrary code and elevate their privileges to system level, potentially compromising the entire system.
Technical details
A heap-based buffer overflow exists in Microsoft Windows Fax Service that can be exploited by an authenticated local attacker to achieve privilege escalation. The vulnerability requires the attacker to already have local access to the system. Successful exploitation allows arbitrary code execution in the context of the Fax Service, which typically runs with elevated privileges, leading to full system compromise. A patch is available from Microsoft.
Affected products
- Microsoft Windows multiple versions (see MSRC advisory)
Timeline
- 2026-09-08: disclosed