Junglewise Threat Intelligence

CVE-2026-69817: Microsoft Windows Bluetooth Port Driver use-after-free privilege escalation

CVE-2026-69817 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Bluetooth Port Driver is a core system component that manages Bluetooth device connectivity on Windows computers. A use-after-free vulnerability allows an authorized local user to execute code with system privileges, potentially compromising the entire device and gaining access to sensitive corporate data or systems.

Technical details

A use-after-free vulnerability exists in the Windows Bluetooth Port Driver, where freed memory is accessed after deallocation. This flaw permits an authenticated local attacker to trigger the vulnerability and achieve privilege escalation from user mode to system privileges. The attack vector is local and requires the attacker to already have user-level access to the system. Successful exploitation allows arbitrary code execution at the kernel level. Patches should be available through Microsoft Security Updates.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats