CVE-2023-24871 is a critical Remote Code Execution (RCE) vulnerability affecting the Windows Bluetooth Service across multiple versions of Windows 10, 11, and Server 2022. With a CVSS score of 8.8 (High), this vulnerability can be exploited by an unauthenticated attacker over an adjacent network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), its high EPSS score and inclusion in Microsoft's March 2023 Patch Tuesday indicate significant potential risk and attention from security researchers. The vulnerability is not currently listed in CISA's KEV catalog, suggesting no known active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.19042.2728CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:* | ||
< 10.0.19044.2728CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.2728CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22000.1696CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.22000.1413CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.