CVE-2023-24871
published 2023-03-14CVE-2023-24871: Windows Bluetooth Service Remote Code Execution Vulnerability
PriorityP353high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
3.22%
86.8th percentile
Windows Bluetooth Service Remote Code Execution Vulnerability
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_20h2 | < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_21h2 | < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_22h2 | < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_11_21h2 | < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_22h2 | < 10.0.22000.1413 | 10.0.22000.1413 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1413 | 10.0.22621.1413 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1607 | 10.0.20348.1607 |
| msrc | windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_10_version_22h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_22h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_22h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_server_2022 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector is Adjacent Network (AV:A) — attacker must be within Bluetooth radio range or on the same restricted network segment to exploit the Windows Bluetooth Service RCE vulnerability. ↗
- →Exploitation path involves programmatic invocation of specific functions in the Windows Bluetooth driver — monitor for anomalous Bluetooth service process behavior or unexpected function calls within the Bluetooth stack. ↗
- ·As of the advisory publication, the vulnerability had NOT been publicly disclosed or exploited in the wild — prioritize patching over active threat hunting for now. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2wcr-hmvp-6j36: Windows Bluetooth Service Remote Code Execution Vulnerability
ghsa_unreviewed·2023-03-14
CVE-2023-24871 [HIGH] GHSA-2wcr-hmvp-6j36: Windows Bluetooth Service Remote Code Execution Vulnerability
Windows Bluetooth Service Remote Code Execution Vulnerability
Microsoft
Windows Bluetooth Service Remote Code Execution Vulnerability
vendor_msrc·2023-03-14·CVSS 8.8
CVE-2023-24871 [HIGH] CWE-190 Windows Bluetooth Service Remote Code Execution Vulnerability
Windows Bluetooth Service Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An unauthorized attacker could exploit the Windows Bluetooth driver vulnerability by programmatically running certain functions that could lead to remote code execution on the Bluetooth component.
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires that an attacker will need to first gain access to the restricted network before running an attack.
Windows Bluetooth Service: Windows Bluetooth Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Releas
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-14
Published