ZeroHour

CVE-2026-69448

mass

Race Condition in Windows Bluetooth Service Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-69448 is a race condition (CWE-362) in the Windows Bluetooth Service, where concurrent operations on a shared resource are improperly synchronized. An attacker who already has low-privilege local access can trigger the flaw, though the high attack complexity means successful timing may require multiple attempts or favorable conditions. Exploitation elevates the attacker's privileges on the local machine, yielding high impact to confidentiality, integrity, and availability of the host. Any Windows system running the Bluetooth Service is potentially affected; the available data does not specify which Windows versions or editions are impacted. There is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

What to do: Apply the Microsoft security update addressing CVE-2026-69448 as soon as it is available, checking Windows Update and Microsoft's advisory for the affected version ranges in your estate. Since exploitation requires pre-existing low-privilege local access and a difficult-to-time race condition, prioritize multi-user endpoints, shared workstations, and kiosk-style systems where local accounts are common. Until patched, restrict local access on sensitive hosts and watch for anomalous privilege-elevation activity involving the Bluetooth Service (bthserv).

Affected
Microsoft Windows (Bluetooth Service)
Estimated exposure
mass≈1 billion+ Windows installations (Bluetooth Service is present by default on Windows client editions) — Windows runs on more than a billion active devices worldwide and the Bluetooth Service ships enabled by default on client editions, so the theoretical exposed base is effectively the entire Windows installed base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.