ZeroHour

CVE-2026-69509

mass

Heap-Based Buffer Overflow LPE in Microsoft Windows Fax Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69509 is a heap-based buffer overflow (CWE-122, with an associated out-of-bounds read, CWE-125) in the Windows Fax Service, an inbox component of Microsoft Windows. The flaw is triggered locally by an already-authenticated, low-privileged user with no user interaction required (AV:L/PR:L/UI:N); the available data does not detail the specific code path that corrupts the heap. A successful exploit allows the attacker to elevate privileges on the local machine, with high impact to the confidentiality, integrity, and availability of that system, reflected in the CVSS 3.1 score of 7.8. Any Windows deployment where the Fax Service is present or enabled is affected, though the data does not enumerate specific affected Windows versions or builds. As of this writing there is no evidence of exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.3% probability of exploitation within 30 days (25th percentile).

What to do: Apply the fix for CVE-2026-69509 via Windows Update once Microsoft's advisory confirms patched builds, prioritizing hosts where untrusted or low-privileged users log on (terminal servers, shared workstations, VDI). Inventory systems with the Fax service enabled or running (e.g., check the 'Fax' service startup type) and consider setting it to disabled where fax functionality is not used. No public PoC or in-the-wild exploitation is known, but monitor Microsoft advisories for updates to affected version ranges.

Affected
Microsoft Windows Fax Service (inbox Windows component)
Estimated exposure
masson the order of 10^8 Windows endpoints carry the inbox Fax Service (Windows' active install base exceeds 1 billion devices); the subset with the service… — The Windows Fax Service is bundled with Windows client and server editions, so the affected component plausibly reaches hundreds of millions of installations worldwide, though only systems with the service enabled/running are locally…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122, CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.