Impact
A race condition in the Windows Bluetooth Service allows an attacker with authorized local access to manipulate shared resources and trigger improper synchronization, resulting in privilege escalation. The flaw is identified as CWE‑362 and CWE‑415.
Affected Systems
The vulnerability affects a wide array of Windows platforms, including Windows 10 versions 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; as well as Windows Server 2019, 2022 and 2025, covering both full installations and Server Core variants.
Risk and Exploitability
The CVSS score of 7 indicates a high severity, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires a local, authorized attacker to trigger a race condition in a running service, the likely attack vector is local and privileged. While exploit code is not publicly confirmed, the high CVSS and the race‑condition nature suggest that an attacker with local access could potentially elevate privileges or execute arbitrary code if the service is mis‑synchronized.
OpenCVE Enrichment