ZeroHour

CVE-2026-69388

mass

Use-After-Free Privilege Escalation in Windows Bluetooth Service

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69388 is a use-after-free (CWE-416) memory-safety flaw in the Windows Bluetooth Service, a component that ships with Microsoft Windows. It can be triggered by an already-authorized local attacker with low privileges on the system, though the high attack-complexity score suggests specific timing or state conditions in the service must be met. Successful exploitation lets the attacker elevate their privileges locally, with high impact on confidentiality, integrity, and availability at the machine level (no sandbox-perimeter escape across systems is described). Any Windows deployment running the Bluetooth Service is potentially affected, and the specific affected Windows version ranges have not been enumerated in the available data. Exploitation status: no public proof-of-concept, no known in-the-wild exploitation, not listed in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (17th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69388 as soon as it is released, prioritizing shared, multi-user, and kiosk-style Windows systems where untrusted users hold local accounts. In the interim, enforce least-privilege local access and verify the Bluetooth Support Service settings on machines where disabling Bluetooth is operationally acceptable. Because no PoC or in-the-wild exploitation is known, this can be handled within normal patch cycles rather than emergency patching.

Affected
Microsoft Windows (Bluetooth Service)
Estimated exposure
mass≈1 billion+ Windows installations (Bluetooth Service is a built-in Windows component; local-access exploitation only) — The Bluetooth Service is part of the default Windows installation, so potential exposure roughly tracks the Windows installed base (order of 10^8–10^9 devices), although only systems where an attacker already holds local low-privileged…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.