Impact
This vulnerability is a heap‑based buffer overflow in the Windows Bluetooth Service. It permits an authorized attacker to trigger an overflow that can lead to arbitrary code execution with elevated privileges. The flaw is documented as CWE‑122.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server 2019, 2022, and 2025, including Server Core images.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local privilege escalation. The EPSS score of less than 1% suggests a low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local and requires an authorized user or a process with sufficient permissions to invoke the vulnerable Bluetooth service. Successful exploitation can grant SYSTEM level access, enabling full control over the machine. This local‑access requirement is inferred from the phrase "authorized attacker" in the description, as the exact privilege threshold is not explicitly stated in the CVE data.
OpenCVE Enrichment