Impact
An improper synchronization in the Windows Bluetooth Service creates a race condition that permits a local user with authorized access to increase privileges. The flaw allows an attacker to alter the execution context and execute code at an elevated level, potentially compromising system integrity and confidentiality. This weakness is classified as a race condition, CWE‑362.
Affected Systems
The vulnerability affects multiple Microsoft Windows releases, including Windows 10 21H2 and 22H2, Windows 11 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core).
Risk and Exploitability
With a CVSS score of 7, the flaw carries a moderate to high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. Because the vulnerability requires local authorized access, the attack vector is likely a local user or elevated background process. Once exploited, an attacker can gain elevated privileges, enabling malicious code execution or system tampering.
OpenCVE Enrichment