CVE-2026-72944
massHeap Buffer Overflow in Windows Fax Service Enables Local Privilege Escalation
CVE-2026-72944 is a heap-based buffer overflow (CWE-122) in the Windows Fax Service, a component Microsoft ships with its Windows operating systems. An attacker with a valid, low-privileged local account can trigger the flaw by getting crafted input processed by the Fax Service, with no user interaction required. Successful exploitation corrupts the service's heap memory and lets the attacker elevate privileges on the local machine, gaining high confidentiality, integrity, and availability impact beyond their original user rights. Any Windows system where the Fax Service component is present is potentially affected, though specific affected build numbers are not detailed in the available data. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, indicating no confirmed exploitation activity to date.
What to do: Apply the Microsoft security update addressing CVE-2026-72944 on all affected Windows systems, prioritizing multi-user hosts such as terminal servers and workstations with untrusted local accounts. As an interim mitigation, consider disabling the Fax service (e.g., 'sc query fax' to check status, then set it to Disabled) on systems that do not use fax functionality. Because exploitation requires local access, limit local logon rights on sensitive machines and verify patch rollout once the update is available.
| Microsoft Windows (Windows Fax Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.