Executive brief
A security vulnerability exists in the Windows component responsible for managing Bluetooth connections. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive files, or install malicious software.
Technical details
A use-after-free vulnerability (CWE-416) exists within the Windows Bluetooth Port Driver. The flaw is triggered when the driver incorrectly manages memory objects during Bluetooth port operations, allowing an attacker to reference memory after it has been freed. To exploit this, an attacker must have local access to the system with low-level privileges and successfully win a race condition or navigate high attack complexity (AC:H). Successful exploitation grants the attacker elevated privileges, potentially reaching SYSTEM-level access, allowing for full system compromise. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory