Executive brief
Windows Fax Service is a Windows system component that processes fax files and communications. A heap-based buffer overflow in this service allows an authorized local user to crash the service or execute arbitrary code with elevated privileges, potentially compromising system integrity and allowing further attacks.
Technical details
A heap-based buffer overflow vulnerability exists in Windows Fax Service, triggered by improper bounds checking when processing specially crafted input. The vulnerability requires local access and authentication on the target system. An authenticated attacker can exploit this flaw to overwrite heap memory and achieve privilege escalation from a standard user context to SYSTEM or another elevated account. The attack vector is local; network exploitation is not possible. Microsoft has released patches to address this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed