ZeroHour

CVE-2026-72944

mass

Heap Buffer Overflow in Windows Fax Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72944 is a heap-based buffer overflow (CWE-122) in the Windows Fax Service, a component Microsoft ships with its Windows operating systems. An attacker with a valid, low-privileged local account can trigger the flaw by getting crafted input processed by the Fax Service, with no user interaction required. Successful exploitation corrupts the service's heap memory and lets the attacker elevate privileges on the local machine, gaining high confidentiality, integrity, and availability impact beyond their original user rights. Any Windows system where the Fax Service component is present is potentially affected, though specific affected build numbers are not detailed in the available data. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, indicating no confirmed exploitation activity to date.

What to do: Apply the Microsoft security update addressing CVE-2026-72944 on all affected Windows systems, prioritizing multi-user hosts such as terminal servers and workstations with untrusted local accounts. As an interim mitigation, consider disabling the Fax service (e.g., 'sc query fax' to check status, then set it to Disabled) on systems that do not use fax functionality. Because exploitation requires local access, limit local logon rights on sensitive machines and verify patch rollout once the update is available.

Affected
Microsoft Windows (Windows Fax Service)
Estimated exposure
masspotentially 100M+ Windows endpoints where the Fax Service component is present (Windows installed base exceeds 1B devices; exact count of systems with the… — The Fax Service ships as part of Windows client SKUs, so the potentially affected population is bounded by the overall Windows installed base of over a billion devices, tempered by the fact that the service is frequently not enabled or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.