CVE-2024-21306 is a spoofing vulnerability in the Microsoft Bluetooth Driver on Windows. Publicly available context identifies the issue only at a high level as a Bluetooth driver spoofing flaw addressed by Microsoft in the January 2024 security updates. Specific technical details about the vulnerable code path, triggering conditions, and protocol handling weakness are not available in the provided information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository, 'blueXploit', is an operational exploit toolkit targeting critical Bluetooth vulnerabilities (notably CVE-2023-45866 and CVE-2024-21306) affecting Android, Linux, macOS, iOS, and Windows. The main exploit (blueXploit.py) leverages flaws in the Bluetooth HID and L2CAP protocols to inject keystrokes into target devices without user interaction or pairing, enabling remote command execution. The toolkit also includes an APK payload injector (injector/apkpwn_injector.py) that automates the creation and injection of Android Meterpreter reverse TCP payloads into APKs, serving them via a local HTTP server for social engineering attacks. Payloads are defined in DuckyScript-like text files and can be customized for specific attack scenarios. The codebase is primarily Python, with supporting Bash scripts for banners. The exploit requires a Linux system with a compatible Bluetooth adapter and several dependencies. The repository is well-documented, with a detailed README explaining the vulnerabilities, affected systems, and attack methodology. The exploit is operational and can be used for real-world attacks in penetration testing or red team scenarios.
This repository implements a proof-of-concept exploit for CVE-2024-21306, targeting Microsoft Windows systems with a specific Bluetooth HID vulnerability. The main script, BadBlue.py, allows an attacker to impersonate a previously paired Bluetooth keyboard and inject arbitrary keystrokes into a Windows machine. The exploit works by spoofing the keyboard's Bluetooth address, connecting to the target Windows device, and sending payloads written in DuckyScript format. The repository includes a sample payload that opens a web browser to a specific URL. The exploit requires the attacker to have a compatible Bluetooth adapter and the target Windows machine to have previously paired with the keyboard (which must be turned off or out of range). The structure of the repository is straightforward: the main exploit logic is in BadBlue.py, payloads are stored in the 'payloads' directory, and usage instructions are provided in the README.md. No hardcoded network endpoints or IP addresses are present; the attack is performed over Bluetooth using user-supplied device addresses.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.