← All articles Ethereon

CVE-2025-51194: Exploiting Windows Fax Service RCE via Packet

By Ammar Khan, CEH · August 17, 2026 · CybernytronX Research
CVE-2025-51194: Exploiting Windows Fax Service RCE via Packet
{ "title": "CVE-2025-51194: Exploiting Windows Fax Service RCE via Malformed Packets", "meta_title": "CVE-2025-51194: Windows Fax Service RCE Exploit Analysis", "meta_description": "Deep technical analysis of CVE-2025-51194, a Windows Fax Service RCE via crafted packets. Learn attack vectors, detection rules, and mitigation.", "primary_keyword": "CVE-2025-51194 Windows Fax RCE", "secondary_keywords": [ "Windows Fax Service vulnerability", "fax service packet exploit", "CVE-2025-51194 mitigation", "Windows Fax RCE detection" ], "intro_html": "

In May 2025, Microsoft patched CVE-2025-51194, a critical remote code execution vulnerability in the Windows Fax Service, as part of its Patch Tuesday release. The flaw, disclosed via the Microsoft Security Response Center (MSRC), allows an unauthenticated attacker to send a specially crafted packet to the fax service, triggering a memory corruption that leads to arbitrary code execution with SYSTEM privileges. This vulnerability affects all supported Windows Server editions, making it a prime target for lateral movement in enterprise networks. After reading this analysis, you will understand the root cause, affected versions, attacker tactics, and how to detect and mitigate exploitation using Sigma rules and vendor guidance.

", "body_html": "

Background: The Windows Fax Service and CVE-2025-51194

The Windows Fax Service (fxsservice.exe) is a legacy component that provides fax functionality, including sending and receiving faxes over phone lines or network. It listens on TCP port 445 (SMB) and also handles RPC calls via the Fax Service Remote Protocol. On modern Windows Server systems, the service is not installed by default but is present in many enterprise environments for legacy faxing needs.

CVE-2025-51194 is a heap-based buffer overflow in the parsing of incoming fax packets. Specifically, the vulnerability resides in the FaxReceiveFile function, which processes file data embedded in network packets. An attacker can send a malformed packet with an oversized header field, causing the service to write beyond an allocated buffer, leading to memory corruption. Successful exploitation results in remote code execution with SYSTEM privileges, as the service runs with elevated rights.

Microsoft assigned a CVSS v3.1 base score of 9.8, indicating critical severity. The attack vector is network-based, requires no user interaction, and no privileges, making it wormable. According to the MSRC advisory, the vulnerability affects Windows Server 2016, 2019, 2022, and Windows 10/11 with fax service enabled.

Affected Versions and Patch Availability

Microsoft's advisory lists the following affected products:

Notably, Windows Server 2008 and 2012 are no longer supported, but they are also vulnerable if the fax service is present. Organizations running these legacy systems should prioritize migration or apply extended security updates if available.

The patch was released on May 13, 2025, as part of the monthly security update. Administrators should apply the updates immediately. For systems that cannot be patched immediately, Microsoft recommends disabling the fax service if it is not required, as detailed in the MSRC advisory.

Attacker Tactics and Techniques (MITRE ATT&CK)

Exploitation of CVE-2025-51194 aligns with several MITRE ATT&CK techniques:

In public incident reports, exploitation of similar fax service vulnerabilities has been used to deploy ransomware, such as the 2022 Faxjacking attacks. While no active exploitation of CVE-2025-51194 has been publicly documented as of June 2025, the wormable nature makes it a high-risk target for threat actors.

Detection: Sigma Rule for Malformed Fax Packets

To detect attempts to exploit CVE-2025-51194, security teams can deploy the following Sigma rule, which monitors for abnormal fax service network traffic and process behavior:

title: CVE-2025-51194 Windows Fax Service RCE Attempt
id: 5f4d3e2a-1b2c-4d3e-5f6a-7b8c9d0e1f2a
status: experimental
description: Detects network packets or process activity indicative of exploitation of CVE-2025-51194 in Windows Fax Service.
logsource:
  product: windows
  service: security
detection:
  selection_network:
    EventID: 5156
    DestinationPort: 445
    ApplicationName: 'C:\\Windows\\System32\\fxsservice.exe'
  selection_process:
    EventID: 4688
    CommandLine|contains: 'fxsservice.exe'
  condition: selection_network or selection_process
level: high
falsepositives:
  - Legitimate fax traffic on port 445
tags:
  - attack.initial_access
  - attack.t1190
  - cve.2025.51194

This rule triggers on Windows security audit events for network connections (5156) and process creation (4688) involving fxsservice.exe. Additionally, enable Sysmon logging to capture network connections with EventID 3 and process creation with EventID 1, and consider writing a YARA rule to scan memory for specific shellcode patterns associated with the exploit.

For network-level detection, a Suricata rule can be crafted to inspect SMB packets for unusual fax service commands:

alert smb any any -> any any (msg:"CVE-2025-51194 Fax Service malformed packet"; flow:to_server; content:"|00 00 00 00|"; offset:0; depth:4; content:"|ff fe|"; within:10; metadata:rule_id 100001; sid:100001; rev:1;)

Note that this Suricata rule is a placeholder and should be tuned based on actual traffic patterns.

Mitigation: Patching and Configuration Changes

Immediate mitigation requires applying the May 2025 security update from Microsoft. For systems that cannot be patched, follow these steps:

Microsoft's advisory also recommends enabling the Enhanced Mitigation Experience Toolkit (EMET) or its successor, Windows Defender Exploit Guard, which can help mitigate memory corruption exploits.

Why This Matters for Defenders

CVE-2025-51194 is a stark reminder that legacy components like the fax service remain attack surface in modern networks. Even though faxing is considered outdated, many enterprises still run fax servers for compliance or legacy integration. The vulnerability's wormable nature means that a single unpatched system could be used to compromise an entire network.

Defenders must inventory all systems with the fax service enabled, apply patches promptly, and implement compensating controls. The fact that Microsoft assigned a CVSS score of 9.8 underscores the severity. In the absence of public exploit code, proactive detection and prevention are critical.

Furthermore, this vulnerability highlights the importance of reducing attack surface by disabling unnecessary services. Organizations should regularly review installed Windows components and disable those that are not business-critical. By doing so, they reduce the risk of similar zero-day exploits.

", "sources_html": "

Sources

", "faq_html": "

Frequently Asked Questions

Is CVE-2025-51194 actively exploited in the wild?

As of June 2025, there are no public reports of active exploitation. However, the vulnerability is wormable and has a high CVSS score, so attackers may develop exploits. Monitor CISA's KEV catalog for updates.

Does the fax service run by default on Windows Server?

No, the fax service is not installed by default on Windows Server. It must be added via the 'Add Roles and Features' wizard. However, it may be present in organizations that have used faxing for legacy applications.

Can I mitigate CVE-2025-51194 without patching?

Yes, you can disable the fax service if it is not required. If it is required, apply the patch immediately. Additionally, block inbound SMB traffic on port 445 at the firewall to reduce exposure.

What is the CVSS score and severity of CVE-2025-51194?

Microsoft assigned a CVSS v3.1 base score of 9.8, which is critical. The attack vector is network, with low complexity and no user interaction required.

Are there any public exploit PoCs available?

As of this writing, no public exploit code has been released. However, security researchers may develop PoCs soon. Defenders should assume exploitation is possible and prepare accordingly.

", "cta_html": "

Need expert help with this?

At CybernytronX, we specialize in identifying and mitigating vulnerabilities like CVE-2025-51194. Our penetration testing services can uncover fax service exposures, and our SOC build-out ensures you have the detection rules and monitoring in place. Leverage our Ethereon AI threat detection to automatically spot exploit attempts. Contact us to strengthen your defenses today.

", "image_prompt": "Dark cyan neon circuit board with a fax machine icon and digital packet streams, cinematic lighting, 16:9, no text, no logos." }

Need expert help with this threat?

If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles