CVE-2017-8628Corporation Microsoft Bluetooth Driver vulnerability

18 documents10 sources
Severity
6.8MEDIUMNVD
EPSS
0.5%
top 35.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateFeb 5

Description

Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages19 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-393v-ghcr-3x2m: Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 82022-05-13

📋Vendor Advisories

1
Microsoft
Microsoft Bluetooth Driver Spoofing Vulnerability2017-09-12

🕵️Threat Intelligence

14
Tenable
Protecting Your Bluetooth Devices from BlueBorne2017-09-15
Tenable
Protecting Your Bluetooth Devices from BlueBorne2017-09-15
Fortinet
BlueBorne May Affect Billions of Bluetooth Devices2017-09-14
Trendmicro
September Patch Tuesday Fixes MS Office Zero-Day2017-09-13
Trendmicro
September Patch Tuesday Fixes MS Office Zero-Day2017-09-13

📄Research Papers

1
arXiv
Threat Modelling in Internet of Things (IoT) Environment Using Dynamic Attack Graphs2024-02-05