Impact
Heap-based buffer overflow in the Windows Fax Service allows an authorized attacker to gain elevated local privileges on affected Windows and Server systems. The flaw is identified as CWE-122 and CWE-125, meaning user-supplied data can corrupt heap memory and lead to arbitrary code execution within the service context.
Affected Systems
Affected products include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server (2012, 2012 R2, 2016, 2019, 2022, 2025) across both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation. With an authorized local attacker able to exploit the heap overflow, there is a clear path to run arbitrary code with elevated privileges. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but that does not reduce the risk to systems that still have the vulnerable service enabled.
OpenCVE Enrichment