CVE-2026-42975
Analyzed Analyzed - Analysis Complete

Heap-based Buffer Overflow in Windows Bluetooth Port Driver

Vulnerability report for CVE-2026-42975, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-23

Assigner: Microsoft Corporation

Description

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-23
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-42975 is a heap-based buffer overflow vulnerability in the Windows Bluetooth Port Driver. This flaw allows an unauthorized attacker to execute arbitrary code on a vulnerable system.

The vulnerability is triggered when the attacker sends specially crafted data to the Bluetooth Port Driver, causing a buffer overflow in the heap memory. This can lead to the execution of malicious code with the privileges of the affected driver.

The attack requires the attacker to be on an adjacent network, meaning they must be physically close to the target system or within the same network segment.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-42975 on a network or system.

To detect this vulnerability, you may need to check for the presence of vulnerable versions of the Windows Bluetooth Port Driver. This typically involves verifying the installed software versions or using vulnerability scanning tools that can identify outdated or unpatched components.

Microsoft may provide detection guidance or updates in their official security advisory. Refer to the Microsoft Update Guide for the latest information on detection, mitigation, and patching.

Impact Analysis

If your system is running a vulnerable version of the Windows Bluetooth Port Driver, this vulnerability could have severe consequences.

  • Remote Code Execution: An attacker could execute arbitrary code on your system, potentially taking full control of it.
  • Data Theft or Manipulation: The attacker could steal sensitive data, install malware, or modify system configurations.
  • System Compromise: The attacker could use the compromised system as a foothold to launch further attacks within your network.

The impact is particularly high because the vulnerability does not require any user interaction or special privileges, and the attacker only needs to be on an adjacent network.

Compliance Impact

This vulnerability could have significant implications for compliance with various standards and regulations, depending on the nature of the data and systems affected.

  • GDPR: If the vulnerable system processes or stores personal data of EU citizens, a successful exploit could lead to a data breach. Under GDPR, organizations must implement appropriate security measures to protect personal data. Failure to patch this vulnerability could result in non-compliance, leading to fines and reputational damage.
  • HIPAA: For organizations handling protected health information (PHI) in the U.S., this vulnerability could result in unauthorized access to PHI. HIPAA requires covered entities to protect PHI from threats, and a breach could lead to penalties and mandatory corrective actions.
  • Other Standards: Compliance frameworks like ISO 27001, NIST, or PCI DSS require organizations to maintain secure systems and protect sensitive data. A successful exploit of this vulnerability could indicate a failure to meet these requirements, potentially leading to compliance violations.

Organizations should assess the risk posed by this vulnerability and take appropriate steps to mitigate it, such as applying patches or implementing compensating controls, to maintain compliance with relevant regulations.

Mitigation Strategies

Apply the security update provided by Microsoft to address CVE-2026-42975. The update can be found in the Microsoft Update Guide for this vulnerability.

  • Ensure all Windows systems are updated with the latest patches from Microsoft.
  • Disable Bluetooth functionality if it is not required for operations, as the vulnerability is exploited over an adjacent network via Bluetooth.
  • Monitor Microsoft's security advisories for any additional guidance or updates related to this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-42975. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart