CVE-2025-27490 is a heap-based buffer overflow in the Windows Bluetooth Service, impacting multiple versions of Windows 10, 11, and Server 2022/2025. This vulnerability carries a CVSS score of 7.8 (HIGH), indicating that an authorized local attacker can achieve high impact to confidentiality, integrity, and availability with low attack complexity. While not currently listed in CISA KEV and lacking public exploit intelligence, it has received some community discussion and media coverage, including mention in a BleepingComputer article regarding Microsoft's April 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.19044.5737CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.5737CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.5189CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22631.5189CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* | ||
< 10.0.26100.3775CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.