CVE-2026-69889
massUse-After-Free Local Privilege Escalation in Windows Bluetooth Service
CVE-2026-69889 is a use-after-free vulnerability (CWE-416) in the Windows Bluetooth Service, a component that ships as part of the Windows operating system. A local attacker who is already authorized on the machine (holds a low-privilege account) can trigger the flaw by causing the service to reuse freed memory, with high attack complexity per the CVSS scoring. Successful exploitation allows the attacker to elevate privileges locally on the compromised host, with high impact on confidentiality, integrity, and availability on that system. Any Windows deployment running the Bluetooth Service is affected; the source data does not enumerate specific affected builds or versions, so defenders should consult Microsoft's advisory for the exact affected range. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Apply the Microsoft security update for CVE-2026-69889 as soon as your patching cycle allows, since the source data does not list specific fixed builds, check Microsoft's advisory for the affected and patched Windows versions. As an interim measure on hosts where Bluetooth is unused, consider disabling the Bluetooth Service or restricting local account access on multi-user systems. Prioritize patching shared servers, VDI hosts, and kiosk-style machines where local low-privilege users exist, and monitor for emergence of public PoCs given the flaw's high-severity rating.
| Microsoft Windows Bluetooth Service (Windows operating systems) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.