CVE-2022-29115
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-29115 is a remote code execution vulnerability affecting the Windows Fax Service. Successful exploitation allows an attacker to execute arbitrary code on the target system. The vulnerability stems from insufficient input validation in the Windows Fax Service, enabling remote attackers to send specially crafted fax documents that trigger the code execution. This issue poses a significant threat, as it can lead to a full system compromise, potentially resulting in data theft or unauthorized access. Microsoft has released a patch to mitigate this vulnerability, and it is strongly recommended that all affected systems be updated promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 7
- Microsoft Windows 10
- Microsoft Windows Server 2012
- Microsoft Windows 8.1
- Microsoft Windows Server 2016
Affected Vendors
- Microsoft