Impact
Use after free in the Windows Bluetooth Service can allow a local attacker to gain elevated privileges. The vulnerability exists when the service incorrectly frees memory, enabling improper use of a dangling pointer. By exploiting this flaw, an attacker who already has the ability to run code on the system can increase their privileges to system level. This weakness is classified as CWE-416 and results in local privilege escalation.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, Server 2022, and Server 2025, including both standard and Server Core installations. The vulnerability is present across both 32‑bit (x86) and 64‑bit (x64) architectures, as well as ARM64 for certain Windows 11 builds.
Risk and Exploitability
The CVSS score of 7.0 indicates a moderate to high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploitation yet. Based on the description, it is inferred that the attack vector is local and requires the attacker to have some legitimate user privileges on the target machine. An attacker would need to trigger the use after free condition within the Bluetooth service, for example by interacting with a malicious Bluetooth device or application. The risk to organizations depends on whether Bluetooth is enabled and whether users can install applications that could exploit the flaw.
OpenCVE Enrichment