CVE-2023-24947
published 2023-05-09CVE-2023-24947: Windows Bluetooth Driver Remote Code Execution Vulnerability
PriorityP349high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.70%
49.0th percentile
Windows Bluetooth Driver Remote Code Execution Vulnerability
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.5921 | 10.0.14393.5921 |
| microsoft | windows_10_1809 | < 10.0.17763.4377 | 10.0.17763.4377 |
| microsoft | windows_10_20h2 | < 10.0.19042.2965 | 10.0.19042.2965 |
| microsoft | windows_10_21h2 | < 10.0.19044.2965 | 10.0.19044.2965 |
| microsoft | windows_10_22h2 | < 10.0.19045.2965 | 10.0.19045.2965 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5921 | 10.0.14393.5921 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.4377 | 10.0.17763.4377 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.4377 | 10.0.17763.4377 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2965 | 10.0.19042.2965 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2965 | 10.0.19044.2965 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2965 | 10.0.19045.2965 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5921 | 10.0.14393.5921 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.4377 | 10.0.17763.4377 |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_10_version_22h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_22h2_for_arm64-based_systems | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Bluetooth Driver Remote Code Execution Vulnerability
vendor_msrc·2023-05-09·CVSS 8.8
CVE-2023-24947 [HIGH] CWE-416 Windows Bluetooth Driver Remote Code Execution Vulnerability
Windows Bluetooth Driver Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
Exploiting this vulnerability requires an attacker to be within proximity of the target system to send and receive radio transmissions.
FAQ: How could an attacker exploit this vulnerability?
An unauthorized attacker could exploit the Windows Bluetooth driver vulnerability by programmatically running certain functions that could lead to remote code execution on the Bluetooth component.
Microsoft Bluetooth Driver: Microsoft Bluetooth Driver
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Les
GHSA
GHSA-mgf5-4cxg-28fx: Windows Bluetooth Driver Remote Code Execution Vulnerability
ghsa_unreviewed·2023-05-09
CVE-2023-24947 [HIGH] GHSA-mgf5-4cxg-28fx: Windows Bluetooth Driver Remote Code Execution Vulnerability
Windows Bluetooth Driver Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-09
Published