peter bassill · operator
$ cve CVE-2024-45434 JSON

CVE-2024-45434

9.8
CRITICAL · CVSS 3.1 · EPSS 7.3% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.31% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploitnone known
Published2025-09-12
Last modified2026-06-17

Affected (1)

VendorProduct
opensynergyblue sdk

References

→ the Explorer  ·  watch your stack  ·  NVD