Impact
A heap-based buffer overflow in the Windows Fax Service allows an authorized local attacker to gain elevated privileges. The flaw falls under CWE‑122, which can enable the attacker to take control of the system with the privileges granted by the process that hosts the Fax Service.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server 2012 through 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability with the potential for local privilege escalation. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation yet. The likely attack vector is a local, authorized user exploiting the Fax Service, which can lead to system compromise if the attacker has sufficient local access.
OpenCVE Enrichment