Impact
The Bluetooth Port Driver contains a use‑after‑free flaw (CWE‑416) that allows an attacker with local authorized access to raise privileges and execute code with SYSTEM rights.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2 and 26H1 (including arm64 and x64 builds), and Windows Server 2022 and 2025 (including Server Core). All these releases ship the vulnerable Bluetooth Port Driver.
Risk and Exploitability
The CVSS score of 7 classifies the issue as Moderate but the local nature of the attack vector means a privileged user can easily compromise the system. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. Adversaries with local credentials can leverage the flaw to gain elevated privileges, potentially installing malware or taking full control of the affected machine.
OpenCVE Enrichment