Executive brief
Microsoft Windows Bluetooth Service contains a race condition vulnerability that allows an authorized local attacker to escalate their privileges on an affected system. An attacker with local access could exploit this synchronization flaw to gain elevated permissions, potentially leading to full system compromise or unauthorized access to sensitive data.
Technical details
A race condition exists in the Windows Bluetooth Service due to improper synchronization of shared resources, allowing concurrent execution that can be exploited for local privilege escalation. The vulnerability requires the attacker to already have local access to the system. Successful exploitation grants elevated privileges on the target machine.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed