Race Condition Vulnerability in Windows Bluetooth Service Affecting Microsoft
CVE-2025-59220

7HIGH

What is CVE-2025-59220?

A vulnerability exists in the Windows Bluetooth Service that results from concurrent execution utilizing a shared resource without proper synchronization. This flaw allows an authorized attacker to exploit the race condition, causing a potential elevation of privileges locally. Effective mitigation is required to secure systems using affected Windows products.

Affected Version(s)

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19043.6332

Windows 10 Version 22H2 x64-based Systems 10.0.19045.0 < 10.0.19044.6332

Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22631.5909

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59220 : Race Condition Vulnerability in Windows Bluetooth Service Affecting Microsoft