Vulnerability Description
Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by the link. Subsequently, attackers can leverage arbitrary file deletion to privilege escalation.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/en/cp-139-10161-fa1b5-2.html
- https://www.twcert.org.tw/tw/cp-132-10160-76012-1.html
FAQ
What is CVE-2024-11857?
CVE-2024-11857 is a vulnerability with a CVSS score of 7.8 (HIGH). Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to ...
How severe is CVE-2024-11857?
CVE-2024-11857 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-11857?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.