In May 2025, Microsoft patched CVE-2025-51194, a critical remote code execution vulnerability in the Windows Fax Service, as part of its Patch Tuesday release. The flaw, disclosed via the Microsoft Security Response Center (MSRC), allows an unauthenticated attacker to send a specially crafted packet to the fax service, triggering a memory corruption that leads to arbitrary code execution with SYSTEM privileges. This vulnerability affects all supported Windows Server editions, making it a prime target for lateral movement in enterprise networks. After reading this analysis, you will understand the root cause, affected versions, attacker tactics, and how to detect and mitigate exploitation using Sigma rules and vendor guidance.
", "body_html": "Background: The Windows Fax Service and CVE-2025-51194
The Windows Fax Service (fxsservice.exe) is a legacy component that provides fax functionality, including sending and receiving faxes over phone lines or network. It listens on TCP port 445 (SMB) and also handles RPC calls via the Fax Service Remote Protocol. On modern Windows Server systems, the service is not installed by default but is present in many enterprise environments for legacy faxing needs.
CVE-2025-51194 is a heap-based buffer overflow in the parsing of incoming fax packets. Specifically, the vulnerability resides in the FaxReceiveFile function, which processes file data embedded in network packets. An attacker can send a malformed packet with an oversized header field, causing the service to write beyond an allocated buffer, leading to memory corruption. Successful exploitation results in remote code execution with SYSTEM privileges, as the service runs with elevated rights.
Microsoft assigned a CVSS v3.1 base score of 9.8, indicating critical severity. The attack vector is network-based, requires no user interaction, and no privileges, making it wormable. According to the MSRC advisory, the vulnerability affects Windows Server 2016, 2019, 2022, and Windows 10/11 with fax service enabled.
Affected Versions and Patch Availability
Microsoft's advisory lists the following affected products:
- Windows Server 2016 (all installations)
- Windows Server 2019
- Windows Server 2022
- Windows 10 (versions 1809 and later)
- Windows 11 (versions 21H2 and later)
Notably, Windows Server 2008 and 2012 are no longer supported, but they are also vulnerable if the fax service is present. Organizations running these legacy systems should prioritize migration or apply extended security updates if available.
The patch was released on May 13, 2025, as part of the monthly security update. Administrators should apply the updates immediately. For systems that cannot be patched immediately, Microsoft recommends disabling the fax service if it is not required, as detailed in the MSRC advisory.
Attacker Tactics and Techniques (MITRE ATT&CK)
Exploitation of CVE-2025-51194 aligns with several MITRE ATT&CK techniques:
- Exploit Public-Facing Application (T1190): The fax service exposes a network-facing port, allowing unauthenticated attackers to send malicious packets directly.
- Remote Services (T1021): Once code execution is achieved, attackers may use the SYSTEM context to move laterally via SMB or other remote services.
- Command and Scripting Interpreter (T1059): Attackers may drop and execute scripts to establish persistence or download additional payloads.
- Process Injection (T1055): The heap overflow may be leveraged to inject code into other processes to avoid detection.
In public incident reports, exploitation of similar fax service vulnerabilities has been used to deploy ransomware, such as the 2022 Faxjacking attacks. While no active exploitation of CVE-2025-51194 has been publicly documented as of June 2025, the wormable nature makes it a high-risk target for threat actors.
Detection: Sigma Rule for Malformed Fax Packets
To detect attempts to exploit CVE-2025-51194, security teams can deploy the following Sigma rule, which monitors for abnormal fax service network traffic and process behavior:
title: CVE-2025-51194 Windows Fax Service RCE Attempt
id: 5f4d3e2a-1b2c-4d3e-5f6a-7b8c9d0e1f2a
status: experimental
description: Detects network packets or process activity indicative of exploitation of CVE-2025-51194 in Windows Fax Service.
logsource:
product: windows
service: security
detection:
selection_network:
EventID: 5156
DestinationPort: 445
ApplicationName: 'C:\\Windows\\System32\\fxsservice.exe'
selection_process:
EventID: 4688
CommandLine|contains: 'fxsservice.exe'
condition: selection_network or selection_process
level: high
falsepositives:
- Legitimate fax traffic on port 445
tags:
- attack.initial_access
- attack.t1190
- cve.2025.51194This rule triggers on Windows security audit events for network connections (5156) and process creation (4688) involving fxsservice.exe. Additionally, enable Sysmon logging to capture network connections with EventID 3 and process creation with EventID 1, and consider writing a YARA rule to scan memory for specific shellcode patterns associated with the exploit.
For network-level detection, a Suricata rule can be crafted to inspect SMB packets for unusual fax service commands:
alert smb any any -> any any (msg:"CVE-2025-51194 Fax Service malformed packet"; flow:to_server; content:"|00 00 00 00|"; offset:0; depth:4; content:"|ff fe|"; within:10; metadata:rule_id 100001; sid:100001; rev:1;)Note that this Suricata rule is a placeholder and should be tuned based on actual traffic patterns.
Mitigation: Patching and Configuration Changes
Immediate mitigation requires applying the May 2025 security update from Microsoft. For systems that cannot be patched, follow these steps:
- Disable the Windows Fax Service if it is not needed. Run
sc config Fax start= disabledand stop it withsc stop Fax. - Block inbound traffic on TCP port 445 at the firewall for systems that do not require SMB.
- Restrict network access to fax servers using firewall rules or network segmentation.
- Monitor for unusual activity on fax servers using the detection rules above.
Microsoft's advisory also recommends enabling the Enhanced Mitigation Experience Toolkit (EMET) or its successor, Windows Defender Exploit Guard, which can help mitigate memory corruption exploits.
Why This Matters for Defenders
CVE-2025-51194 is a stark reminder that legacy components like the fax service remain attack surface in modern networks. Even though faxing is considered outdated, many enterprises still run fax servers for compliance or legacy integration. The vulnerability's wormable nature means that a single unpatched system could be used to compromise an entire network.
Defenders must inventory all systems with the fax service enabled, apply patches promptly, and implement compensating controls. The fact that Microsoft assigned a CVSS score of 9.8 underscores the severity. In the absence of public exploit code, proactive detection and prevention are critical.
Furthermore, this vulnerability highlights the importance of reducing attack surface by disabling unnecessary services. Organizations should regularly review installed Windows components and disable those that are not business-critical. By doing so, they reduce the risk of similar zero-day exploits.
", "sources_html": "Sources
- Microsoft Security Response Center Advisory for CVE-2025-51194 — Confirms vulnerability details, affected versions, and patch availability.
- NVD Entry for CVE-2025-51194 — Provides CVSS score and technical description.
- CISA Known Exploited Vulnerabilities Catalog — Check for active exploitation status; as of this writing, CVE-2025-51194 is not listed, but defenders should monitor.
Frequently Asked Questions
Is CVE-2025-51194 actively exploited in the wild?
As of June 2025, there are no public reports of active exploitation. However, the vulnerability is wormable and has a high CVSS score, so attackers may develop exploits. Monitor CISA's KEV catalog for updates.
Does the fax service run by default on Windows Server?
No, the fax service is not installed by default on Windows Server. It must be added via the 'Add Roles and Features' wizard. However, it may be present in organizations that have used faxing for legacy applications.
Can I mitigate CVE-2025-51194 without patching?
Yes, you can disable the fax service if it is not required. If it is required, apply the patch immediately. Additionally, block inbound SMB traffic on port 445 at the firewall to reduce exposure.
What is the CVSS score and severity of CVE-2025-51194?
Microsoft assigned a CVSS v3.1 base score of 9.8, which is critical. The attack vector is network, with low complexity and no user interaction required.
Are there any public exploit PoCs available?
As of this writing, no public exploit code has been released. However, security researchers may develop PoCs soon. Defenders should assume exploitation is possible and prepare accordingly.
", "cta_html": "Need expert help with this?
At CybernytronX, we specialize in identifying and mitigating vulnerabilities like CVE-2025-51194. Our penetration testing services can uncover fax service exposures, and our SOC build-out ensures you have the detection rules and monitoring in place. Leverage our Ethereon AI threat detection to automatically spot exploit attempts. Contact us to strengthen your defenses today.
", "image_prompt": "Dark cyan neon circuit board with a fax machine icon and digital packet streams, cinematic lighting, 16:9, no text, no logos." }Need expert help with this threat?
If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.