CVE-2026-58538
Analyzed Analyzed - Analysis Complete

Heap-based Buffer Overflow in Windows Bluetooth Service

Vulnerability report for CVE-2026-58538, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 17 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-58538 is a heap-based buffer overflow vulnerability in the Windows Bluetooth Service. This flaw allows an authorized attacker with local access to exploit the service and elevate their privileges on the affected system.

A heap-based buffer overflow occurs when a program writes more data to a buffer than it can hold, corrupting adjacent memory. In this case, the vulnerability exists in the Windows Bluetooth Service, which could be exploited to gain higher-level permissions than originally granted.

  • The attacker must be authorized (have some level of access) and local to the system to exploit this vulnerability.
  • Successful exploitation could lead to privilege escalation, allowing the attacker to perform actions with elevated permissions.
Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-58538 on a network or system. Detection typically involves checking the installed version of the Windows Bluetooth Service or using vulnerability scanning tools that can identify unpatched systems.

For Microsoft-specific guidance, refer to the official update guide, which may provide details on how to verify if a system is vulnerable or has been patched.

Impact Analysis

If you are using a system with the vulnerable Windows Bluetooth Service, this vulnerability could have several impacts:

  • An attacker with local access and some level of authorization could exploit this flaw to gain elevated privileges on your system.
  • Elevated privileges could allow the attacker to execute arbitrary code, install malware, or access sensitive data that would otherwise be restricted.
  • The attacker could potentially take full control of the affected system, leading to data breaches or further compromise of connected systems.

This vulnerability is particularly concerning in environments where multiple users share a system or where Bluetooth services are enabled by default.

Compliance Impact

This vulnerability could impact compliance with several common standards and regulations, depending on the context of its exploitation:

  • GDPR (General Data Protection Regulation): If the vulnerability is exploited to access or exfiltrate personal data of EU citizens, it could lead to a data breach. GDPR requires organizations to implement appropriate security measures to protect personal data, and failure to patch such vulnerabilities could be seen as a violation.
  • HIPAA (Health Insurance Portability and Accountability Act): In healthcare environments, if the vulnerability is exploited to access protected health information (PHI), it could result in a breach of HIPAA's security and privacy rules. Covered entities must ensure the confidentiality, integrity, and availability of PHI, and this vulnerability could undermine those requirements.
  • Other standards like ISO 27001, NIST, or PCI DSS may also be affected if the vulnerability leads to unauthorized access or data breaches. These standards require organizations to maintain secure systems and address vulnerabilities promptly.

Failure to mitigate this vulnerability could result in non-compliance, potential fines, or legal consequences, especially if it leads to a data breach involving sensitive or regulated information.

Mitigation Strategies

To mitigate CVE-2026-58538, apply the security update provided by Microsoft as soon as possible. The update addresses the heap-based buffer overflow in the Windows Bluetooth Service.

  • Visit the Microsoft Security Response Center (MSRC) update guide for CVE-2026-58538 to download and install the patch.
  • Ensure all systems running the affected Windows Bluetooth Service are updated to the latest secure version.
  • Restrict local access to authorized users only, as the vulnerability requires local access to exploit.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58538. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart