Executive brief
Windows Bluetooth Service is a core operating system component that manages wireless Bluetooth connectivity for peripherals. A use-after-free memory vulnerability allows an authorized local user to crash the service or execute code with elevated privileges, potentially leading to full system compromise.
Technical details
A use-after-free vulnerability exists in the Windows Bluetooth Service that can be triggered by an authorized local attacker. The vulnerability occurs due to improper memory management where freed memory is accessed after deallocation. An attacker with local system access can exploit this flaw to achieve privilege escalation from a standard user context to a higher privilege level, potentially gaining SYSTEM-level access. The attack requires local access and prior authorization on the target system.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed