Executive brief
A security vulnerability exists in the Windows Bluetooth Service, which manages wireless connections to devices like headphones and keyboards. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install malicious software, view or delete sensitive data, or disrupt business operations.
Technical details
A use-after-free vulnerability (CWE-416) exists within the Windows Bluetooth Service. The flaw is triggered when the service incorrectly manages memory objects during Bluetooth operations, allowing an attacker to execute code in a privileged context. To exploit this, an attacker must first gain local access to the target system with low-privileged user credentials. Successful exploitation grants the attacker SYSTEM-level privileges, enabling full compromise of the host's integrity, confidentiality, and availability. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory