PT-2024-1122 · Microsoft · Bluetooth Driver+1

Marc Newlin

·

Published

2024-01-09

·

Updated

2025-09-05

·

CVE-2024-21306

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Bluetooth Driver (affected versions not specified)
Description The issue is related to errors in the representation of information by the user interface in the Microsoft Bluetooth Driver. It allows a remote attacker to conduct spoofing attacks. The vulnerability can be exploited to pair a virtual Bluetooth keyboard without authentication or user confirmation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

BDU:2024-00406
CVE-2024-21306

Affected Products

Bluetooth Driver
Windows