Impact
The vulnerability is a use‑after‑free bug in the Windows Bluetooth Port Driver that an attacker can exploit to gain higher privileges on a local system. By leveraging the released kernel memory, the attacker can execute arbitrary code with the driver's elevated rights, effectively bypassing user‑level access controls. The weakness maps to CWE‑416 and may allow a local user to attain system‑wide privileges or alter system configuration and data.
Affected Systems
Microsoft Windows 10 (Version 1607, 1809, 21H2, 22H2), Windows 11 (Version 23H2, 24H2, 25H2, 26H1), and Windows Server – 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core editions). All affected releases are listed under the Windows Bluetooth Port Driver component and are addressed in the vendor’s cumulative update for this CVE.
Risk and Exploitability
The CVSS score of 7 indicates a high severity when an authorized local attacker obtains the flaw. EPSS data is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, implying no documented mass exploitation yet. The attack vector is inferred to be local only, requiring the attacker to have physical or remote access to the target machine and to have sufficient permissions to load unsigned code. Given the seriousness of the privilege escalation and the lack of mitigation in unpatched systems, the risk remains significant until a vendor patch is applied.
OpenCVE Enrichment