go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Realtek Bluetooth HCI Adaptor - Privilege Escalation

TVN ID TVN-202506001
CVE ID CVE-2024-11857
CVSS 7.8 (High)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Bluetooth HCI Adaptor before version 1.1.73.1
Description Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by the link. Subsequently, attackers can leverage arbitrary file deletion to privilege escalation.
Solution Update to version 1.1.73.1 or later
Credit Crispr Xiang
Public Date 2025-06-02
Top