PT-2025-29084 · Opensynergy · Bluesdk
Published
2025-07-07
·
Updated
2025-09-17
·
CVE-2024-45434
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
OpenSynergy BlueSDK (aka Blue SDK) versions through 6.x
Description:
The vulnerability resides within the BlueSDK Bluetooth stack and is due to a use-after-free condition. This flaw occurs because of a lack of validation to confirm the existence of an object before operations are performed on it. An attacker can leverage this to achieve remote code execution within the context of the user account under which the Bluetooth process is running.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bluesdk