CVE-2026-69621
massHeap Buffer Overflow in Windows Fax Service Enables Local Privilege Escalation
A heap-based buffer overflow (CWE-122) exists in the Microsoft Windows Fax Service. An authorized attacker who already has low-privileged local access could trigger the flaw by getting crafted input processed by the Fax Service; the high attack-complexity score (AC:H) indicates the exploit depends on relatively specific runtime conditions, though no user interaction is required. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability of the system. Any Windows system on which the Fax Service is installed and reachable is potentially affected, with workstations and servers used in multi-user or shared-access environments the most relevant targets. As of this snapshot there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation odds at only 0.3%, so exploitation is currently considered unlikely.
What to do: Track Microsoft's advisory for CVE-2026-69621 and apply the patch via Windows Update once released, prioritizing shared and multi-user systems where local privilege escalation has the most value. As an interim mitigation, disable the Fax service on systems that do not need fax functionality and confirm it is not running on critical servers. Given the low EPSS score and absence of public PoCs, routine patch-cycle handling is reasonable, but re-check KEV and PoC status if exploitation activity appears.
| Microsoft Windows (Fax Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.