ZeroHour

CVE-2026-69398

mass

Race Condition in Windows Bluetooth Service Allows Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-69398 is a race condition (CWE-362, with associated CWE-415) in the Windows Bluetooth Service, caused by improper synchronization when multiple threads access a shared resource. An authorized attacker who already has low-privileged local access to a vulnerable Windows system can trigger the flaw by timing their operations to win the race, though the high attack-complexity rating (AC:H) indicates reliable exploitation requires specific timing conditions. Successful exploitation lets the attacker elevate privileges locally, with high impact on the confidentiality, integrity, and availability of the compromised system. Affected systems are Windows installations running the Bluetooth Service, although the available data does not enumerate which specific Windows editions or version ranges are impacted. As of this analysis there is no known public proof-of-concept, the vulnerability is not in CISA's KEV catalog, and EPSS assigns a 0.2% probability of exploitation within 30 days (9th percentile), indicating no known active exploitation.

What to do: Apply Microsoft's security update for this vulnerability as soon as it is issued (normally via Windows Update on the monthly Patch Tuesday), prioritizing shared workstations, kiosks, and multi-user systems where untrusted users have local logon rights. Until patched, limit local interactive access on Bluetooth-enabled Windows hosts and verify with vendor advisories which specific Windows versions are in scope, since the published data does not list them.

Affected
Microsoft Windows Bluetooth Service (Windows operating systems)
Estimated exposure
mass≈1 billion+ Windows installations (the global Windows desktop install base) — Microsoft Windows runs on more than a billion active devices worldwide and the Bluetooth Service is present by default on Windows desktop and laptop builds, so the order of magnitude follows the overall Windows install base rather than a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-362, CWE-415
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.