CVE-2026-23671
vulnerability analysis and mitigation

Overview

CVE-2026-23671 is a race condition and use-after-free vulnerability in the Windows Bluetooth RFCOM Protocol Driver that allows an authorized local attacker with low privileges to elevate privileges on the affected system. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025. It carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC).

Technical details

The vulnerability is rooted in improper synchronization when multiple threads concurrently access shared resources within the Windows Bluetooth RFCOM Protocol Driver, classified as CWE-362 (Race Condition) and CWE-416 (Use After Free). An attacker who wins the race condition can trigger a use-after-free condition in kernel memory, enabling code execution at the kernel level. Exploitation requires local access and low-level user privileges, but no user interaction is needed; however, the high attack complexity (AC:H) means the attacker must precisely time the race condition to succeed. No public proof-of-concept code has been identified (Microsoft MSRC).

Impact

Successful exploitation allows a low-privileged local attacker to escalate to kernel-level code execution, potentially gaining complete control over the affected system. This could result in high confidentiality, integrity, and availability impact — enabling the attacker to read or exfiltrate sensitive data, modify or delete system files, install malware or backdoors, and disrupt system operations. While the attack is local in scope, a compromised system could serve as a pivot point for lateral movement within a network (Microsoft MSRC).

Exploitation steps

  1. Gain Local Access: Obtain a low-privileged local user account on a vulnerable Windows system (Windows 10, 11, or Server 2016–2025) that has not applied the March 2026 security updates.
  2. Identify the Target Driver: Confirm the Windows Bluetooth RFCOM Protocol Driver is active on the target system, which is typical on systems with Bluetooth hardware enabled.
  3. Craft Race Condition Trigger: Develop or obtain code that spawns multiple threads to concurrently interact with the RFCOM driver's shared resources, exploiting the lack of proper synchronization to create a time-of-check/time-of-use (TOCTOU) window.
  4. Win the Race Condition: Repeatedly execute the concurrent thread operations to trigger the race condition at the precise moment, causing a use-after-free condition in kernel memory.
  5. Achieve Kernel Code Execution: Leverage the use-after-free to overwrite kernel memory structures or function pointers, redirecting execution flow to attacker-controlled code running at kernel privilege level.
  6. Escalate Privileges: Use the kernel-level access to elevate the attacker's process token to SYSTEM, enabling full control over the compromised host (Microsoft MSRC).

Indicators of compromise

  • Logs: Windows Security Event Log entries showing unexpected privilege escalation (Event ID 4672 – Special privileges assigned to new logon) from low-privileged accounts; kernel crash dumps (BSOD) referencing the Bluetooth RFCOM driver (rfcomm.sys) may indicate failed exploitation attempts.
  • Process: Unusual processes spawned with SYSTEM-level privileges from a standard user context; unexpected child processes of Bluetooth-related services.
  • File System: Unexpected modifications to or loading of kernel drivers; new scheduled tasks or services created by non-administrative accounts following a privilege escalation event.
  • Network: Outbound connections initiated by SYSTEM-level processes to unknown external IPs shortly after local Bluetooth driver interactions, potentially indicating post-exploitation activity.

Mitigation and workarounds

Microsoft released patches on March 10, 2026, addressing this vulnerability across all affected platforms. Administrators should apply the following patched build versions: Windows 10 1607 (10.0.14393.8957), Windows 10 1809/Server 2019 (10.0.17763.8511), Windows 10 21H2 (10.0.19044.7058), Windows 10 22H2 (10.0.19045.7058), Windows 11 23H2 (10.0.22631.6783), Windows 11 24H2 (10.0.26100.7979), Windows 11 25H2 (10.0.26200.7979), Windows 11 26H1 (10.0.28000.1719), Windows Server 2016 (10.0.14393.8957), Windows Server 2022 (10.0.20348.4893), Windows Server 2022 23H2 (10.0.25398.2207), and Windows Server 2025 (10.0.26100.32522). As interim mitigations, organizations should enforce the principle of least privilege, restrict local user access on sensitive systems, and consider disabling Bluetooth on systems where it is not required (Microsoft MSRC).

Community reactions

CVE-2026-23671 was covered as part of broader March 2026 Patch Tuesday roundups by security outlets including BleepingComputer, CyberSecurityNews, Rapid7, Sophos, and Zero Day Initiative, which collectively noted the patch addressed 79–84 vulnerabilities including two zero-days (unrelated to this CVE). No specific researcher commentary or notable social media discussion focused exclusively on this vulnerability was identified, consistent with its lack of public exploit code and low EPSS score (Rapid7 Blog, Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management