ActiveFax Server Unquoted Service Path Vulnerability in ActiveFaxServiceNT

Vulnerability

A vulnerability exists in ActiveFax Server version 6.92 Build 0316, specifically within the ActiveFaxServiceNT service. This vulnerability arises from an unquoted service path, which local attackers could exploit to execute arbitrary code. By injecting malicious executables into the unquoted binary path, attackers may execute these files with elevated administrative privileges.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution with administrative rights.

Reproduction

The vulnerability can be reproduced by querying the service configuration of 'ActiveFaxServiceNT' using the Service Control Manager (SC) command. The unquoted binary path can then be exploited by placing a malicious executable in a location that the service will execute with elevated privileges.

Added: Feb 11, 2026, 3:34 PM
Updated: Feb 11, 2026, 3:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
3.4
remediation
0.0
relevance
2.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.