Executive brief
A security vulnerability exists in the Bluetooth drivers used by certain Dynabook and Toshiba laptops manufactured between 2017 and 2022. If an attacker already has high-level administrative access to a computer, they can exploit this flaw to run malicious code with even deeper system privileges. This could allow them to gain full control over the device, bypass security protections, or cause the system to crash.
Technical details
A stack-based buffer overflow (CWE-121) exists in the Dynabook Bluetooth ACPI drivers TOSRFEC.SYS and DRFEC.SYS. The vulnerability is triggered when the driver processes specific registry values, which can be manipulated by an attacker. Exploitation requires local access and high privileges (PR:H), such as administrative rights, to modify the registry. Successful exploitation allows for arbitrary code execution in the context of the kernel or the driver, potentially leading to full system compromise. The issue affects various Dynabook/Toshiba PC models manufactured between 2017 and April 2022. Users are advised to update to DRFEC.SYS version v11.0.2.3 or later via Windows Update.
Affected products
- Dynabook Inc. Bluetooth ACPI Driver (TOSRFEC.SYS) All versions
- Dynabook Inc. Bluetooth ACPI Driver (DRFEC.SYS) v11.0.0.0 and earlier
Timeline
- 2026-04-13: advisory: Initial advisory published by Dynabook and JPCERT/CC
- 2026-04-13: disclosed