Faxploit Fax-based Malware Delivery Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The Check Point researchers claim they are able to execute files in the form of a fax on any fax machine that receives them. Fax machines transmit images by scanning the image, encoding the image data before sending it over a network to a recipient machine, which then decodes the data and reconstructs the original image. The researchers discovered that by encoding a specially crafted file within an image and faxing it to a recipient machine they were able to execute that file on that machine. When the recipient machine decodes the file it inadvertently executes it as well; this could allow a remote attacker to send malicious files to a target fax machine, where they would then be executed.
As of 2017, the NHS has less than 9000 fax machines present across the estate, with a large percentage of these being multi-function office printers.
For further information
Remediation steps
Last edited: 17 February 2020 12:43 pm