CVE-2023-24871 is a remote code execution vulnerability in the Windows Bluetooth Service. Technical details regarding the affected function, attack method, and affected Windows versions are not available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a comprehensive, weaponized exploit for CVE-2023-24871, a critical vulnerability in the Windows Bluetooth stack affecting Windows 10 and 11. The exploit supports both Local Privilege Escalation (LPE) and Remote Code Execution (RCE) scenarios. The LPE exploit is implemented in the 'lpe/exploit' directory and consists of several modules: - bthlpe_master.exe: Main orchestrator process. - bthlpe_payload.dll: Injected into StartMenuExperienceHost.exe to trigger the vulnerability via a crafted RPC call to bthserv. - bthlpe_harness.dll: Loaded into bthserv to execute a post-exploitation step. - bthlpe_juicypotato.exe: Uses JuicyPotatoNG to escalate from LOCAL SERVICE to SYSTEM. The exploit chain involves DLL injection, heap grooming, and privilege escalation, ultimately providing a SYSTEM shell on the target. The exploit is robust, with error handling and process synchronization via named events. The RCE PoC, found in the 'rce/poc' directory, uses the open-source btstack project to send crafted Bluetooth LE advertisement data to a vulnerable target, triggering heap corruption in either user-mode (bthserv) or kernel-mode (bthport.sys). The RCE scenario requires two Bluetooth 5.0-capable systems and specific driver versions. The repository is well-structured, with separate directories for LPE and RCE, detailed documentation, and build scripts for Windows and cross-platform compilation. The code is primarily in C/C++, with some batch scripts and CMake files. Entry points include main exploit orchestrators, DLLs for injection, and PoC executables. Notable endpoints include Windows system processes (StartMenuExperienceHost.exe, bthserv), DLLs (biwinrt.dll), and kernel drivers (bthport.sys). The exploit is operational and weaponized, providing reliable privilege escalation and remote attack capabilities against unpatched Windows systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.