Impact
The Windows Bluetooth Service contains a use‑after‑free flaw that can be triggered by a local user who is authorized to use Bluetooth. When the service frees memory that remains reachable, an attacker can corrupt or overwrite data used in subsequent operations, allowing execution of arbitrary code or manipulation of privileged data within the service context. This renders a non‑privileged local account able to gain elevated privileges on the host system, a classic instance of CWE‑416.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 7 indicates high severity, yet the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, implying no publicly documented exploitation yet. The attack vector is inferred to be local, requiring the attacker to have legitimate access to the target computer and the ability to send crafted Bluetooth requests to the service. Successful exploitation would lead to privilege escalation for the local user, with potential impact on confidentiality, integrity, and availability of the system.
OpenCVE Enrichment