PT-2025-29084 · Opensynergy · Bluesdk

Published

2025-07-07

·

Updated

2025-09-17

·

CVE-2024-45434

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: OpenSynergy BlueSDK (aka Blue SDK) versions through 6.x
Description: The vulnerability resides within the BlueSDK Bluetooth stack and is due to a use-after-free condition. This flaw occurs because of a lack of validation to confirm the existence of an object before operations are performed on it. An attacker can leverage this to achieve remote code execution within the context of the user account under which the Bluetooth process is running.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2025-09385
CVE-2024-45434

Affected Products

Bluesdk