MSRC compact vulnerability detail

CVE-2022-35820 · Windows Bluetooth Driver Elevation of Privilege Vulnerability

No description was published by MSRC.

Severity
Important
Impact
Elevation of Privilege
CVSS
7.8 base · 6.8 temporal
Release
2022-08-09
Signals
Microsoft Bluetooth Driver Elevation of Privilege Exploited: No Publicly disclosed: No Exploitability: Exploitation More Likely
CWE
No CWE data published.
Patch Diff
Loading module diff metadata...
Resolved binary override
Use this when the MSRC module name cannot be mapped automatically or the resolved binary looks wrong.
Old version New version
Description
No description was published by MSRC.
FAQ / Articles
Bluetooth Driver Reg Key Read Write
What privileges could be gained by an attacker who successfully exploited the vulnerability? An authorized local attacker could exploit this Windows Bluetooth driver vulnerability by programmatically running certain functions to arbitrarily gain registry key creation and deletion in the bthport.sys driver.
Workaround
The following workaround may be helpful in your situation. In all cases, Microsoft strongly recommends that you install the updates for this vulnerability as soon as possible even if you plan to leave this workaround in place: Disable the ability of child keys to allow full owner or creator permissions Note Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk. For information about how to edit the registry, view the "Changing Keys and Values" Help topic in Registry Editor (Regedit.exe) or view the "Add and Delete Information in the Registry" and "Edit Registry Data" Help topics in Regedt32.exe. Click Start, click Run, type Regedit in the Open box, and then click OK. Locate and then click the following registry subkey: HKLM: \SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters Open Permissions Open Advanced Click Disable inheritance Select Convert to explicit Remove Creator/Owner from the Permissions. Impact of workaround All child keys will no...