CVE-2021-24077
published 2021-02-25CVE-2021-24077: Windows Fax Service Remote Code Execution Vulnerability
PriorityP259critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.69%
84.2th percentile
Windows Fax Service Remote Code Execution Vulnerability
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_7 | >= 6.1.0 < publication | publication |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < publication | publication |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Check if the Fax service is running — systems with the Fax service in 'Running' state are vulnerable; absence of the service or non-running status indicates no current exposure ↗
- →For Windows 11 and Windows 10, the FAX service is not installed by default — focus detection/hunting on systems where Windows Fax and Scan has been explicitly enabled ↗
- ·Exploit status is 'Exploitation Less Likely' for both latest and older software releases, and has not been publicly disclosed or exploited in the wild as of advisory publication ↗
- ·The vulnerability only applies to the Windows Fax Service component; systems without this role/feature enabled are not affected ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Fax Service Remote Code Execution Vulnerability
vendor_msrc·2021-02-09·CVSS 9.8
CVE-2021-24077 [CRITICAL] Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
FAQ: In what scenarios is my computer vulnerable?
For Windows 11 and Windows 10 the FAX service is not installed by default. For the vulnerability to be exploitable, the Windows Fax and Scan feature needs to be enabled, and the Fax service needs to be running. Systems that do not have the Fax service running are not vulnerable.
How can I verify whether the Fax service is running?
Hold the Windows key and press R on your keyboard. This will open the Run dialog.
Type services.msc and press Enter to open the Services window.
Scroll through the list and locate the Fax service.
If the Fax service is not listed, Windows Fax and Scan is not enabled and the system is not vulnerable.
If the Fax service is listed but the status is not Runnin
GHSA
GHSA-9pqr-g6m6-mhm5: Windows Fax Service Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24077
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2021-1722 [CRITICAL] GHSA-9pqr-g6m6-mhm5: Windows Fax Service Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24077
Windows Fax Service Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24077.
GHSA
GHSA-mpm7-qfrh-w576: Windows Fax Service Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1722
ghsa_unreviewed·2022-05-24·CVSS 8.1
CVE-2021-24077 [HIGH] GHSA-mpm7-qfrh-w576: Windows Fax Service Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1722
Windows Fax Service Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1722.
No detection rules found.
No public exploits indexed.
Qualys
February 2021 Patch Tuesday – 56 Vulnerabilities, 11 Critical, Adobe
blogs_qualys·2021-02-09·CVSS 7.8
CVE-2021-24074 [HIGH] February 2021 Patch Tuesday – 56 Vulnerabilities, 11 Critical, Adobe
This month’s Microsoft Patch Tuesday addresses 56 vulnerabilities, of which 11 are rated as Critical. Adobe released patches today for Reader, Acrobat, Magento, Photoshop, Animate, Illustrator, and Dreamweaver.
## TCP/IP Trio
Microsoft released a set of fixes affecting Windows TCP/IP implementation that include two Critical Remote Code Execution (RCE) vulnerabilities (CVE-2021-24074 and CVE-2021-24094) and an Important Denial of Service (DoS) vulnerability (CVE-2021-24086). While there is no evidence that these vulnerabilities are exploited in wild, these vulnerabilities should be prioritized given their impact.
## Windows Fax Service
Microsoft released patches to fix a remote code execution vulnerability in Windows Fax Service (CVE-2021-24077). This vulnerability has a CVSSv3 base sco
Qualys
February 2021 Patch Tuesday – 56 Vulnerabilities, 11 Critical, Adobe | Qualys
blogs_qualys·2021-02-09·CVSS 7.8
CVE-2021-24074 [HIGH] February 2021 Patch Tuesday – 56 Vulnerabilities, 11 Critical, Adobe | Qualys
This month’s Microsoft Patch Tuesday addresses 56 vulnerabilities, of which 11 are rated as Critical. Adobe released patches today for Reader, Acrobat, Magento, Photoshop, Animate, Illustrator, and Dreamweaver.
### TCP/IP Trio
Microsoft released a set of fixes affecting Windows TCP/IP implementation that include two Critical Remote Code Execution (RCE) vulnerabilities (CVE-2021-24074 and CVE-2021-24094) and an Important Denial of Service (DoS) vulnerability (CVE-2021-24086). While there is no evidence that these vulnerabilities are exploited in wild, these vulnerabilities should be prioritized given their impact.
### Windows Fax Service
Microsoft released patches to fix a remote code execution vulnerability in Windows Fax Service (CVE-2021-24077). This vulnerability has a CVSSv3 base s
2021-02-25
Published