Executive brief
Windows Bluetooth Service contains a race condition vulnerability in its handling of shared resources. An authorized local user can exploit this synchronization flaw to escalate their privileges on an affected system, potentially gaining administrative access and full control over the computer.
Technical details
This vulnerability is a classic race condition (CWE-362) in the Windows Bluetooth Service caused by improper synchronization of shared resources. The flaw allows an authorized local attacker to trigger a time-of-check-time-of-use (TOCTOU) condition, bypassing privilege checks and achieving local privilege escalation. Exploitation requires local access to the system and an existing user account; remote exploitation is not possible. An attacker can leverage this to execute arbitrary code with elevated (SYSTEM or administrative) privileges. Microsoft has released security updates to address this vulnerability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed