CVE-2026-69509
massHeap-Based Buffer Overflow LPE in Microsoft Windows Fax Service
CVE-2026-69509 is a heap-based buffer overflow (CWE-122, with an associated out-of-bounds read, CWE-125) in the Windows Fax Service, an inbox component of Microsoft Windows. The flaw is triggered locally by an already-authenticated, low-privileged user with no user interaction required (AV:L/PR:L/UI:N); the available data does not detail the specific code path that corrupts the heap. A successful exploit allows the attacker to elevate privileges on the local machine, with high impact to the confidentiality, integrity, and availability of that system, reflected in the CVSS 3.1 score of 7.8. Any Windows deployment where the Fax Service is present or enabled is affected, though the data does not enumerate specific affected Windows versions or builds. As of this writing there is no evidence of exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.3% probability of exploitation within 30 days (25th percentile).
What to do: Apply the fix for CVE-2026-69509 via Windows Update once Microsoft's advisory confirms patched builds, prioritizing hosts where untrusted or low-privileged users log on (terminal servers, shared workstations, VDI). Inventory systems with the Fax service enabled or running (e.g., check the 'Fax' service startup type) and consider setting it to disabled where fax functionality is not used. No public PoC or in-the-wild exploitation is known, but monitor Microsoft advisories for updates to affected version ranges.
| Microsoft Windows Fax Service (inbox Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122, CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.