CVE-2026-69817
massUse-After-Free Local Privilege Escalation in Windows Bluetooth Port Driver
CVE-2026-69817 is a use-after-free (CWE-416) memory corruption flaw in the Windows Bluetooth Port Driver, the kernel component that handles Bluetooth port communications. A local, authenticated attacker who has already gained low-privilege code execution on a machine can trigger the flaw by causing the driver to use memory that has been freed; the high attack-complexity rating suggests this likely requires carefully timed conditions such as a race or specific driver state. Successful exploitation lets the attacker elevate their privileges to higher (kernel/SYSTEM) rights on that local machine, giving them full control of the host, though they cannot exploit it remotely. Any Windows system running the affected Bluetooth Port Driver is exposed, with the main risk on multi-user machines, shared workstations, RDS hosts, and endpoints where untrusted users can log on. As of now there is no known exploitation: it is not in CISA's KEV, no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at just 0.3%.
What to do: Apply Microsoft's security update for the affected Windows Bluetooth Port Driver as soon as it is available, prioritizing hosts where untrusted or low-privilege users can log on interactively (shared workstations, kiosks, terminal servers). Check the Microsoft advisory for the exact affected and fixed builds once published, since the source data here did not include version ranges. Until patched, restrict local logon rights on sensitive machines and monitor for any public proof-of-concept or in-the-wild exploitation.
| Microsoft Windows Bluetooth Port Driver | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.