MEDIUM 6.3 Microsoft PoC

CVE-2023-45866

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection and accept HID keyboard reports potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

Microsoft Security Update 2023-Dec: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection and accept HID keyboard reports potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

Affected Products

References

Published: 2023-12-12 · Source: Microsoft · Feed updated: 2026-09-03
This medium severity vulnerability with a CVSS score of 6.3 was published on 2023-12-12 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 7.9% (top 6% of all CVEs by exploitation probability). Affected: cbl2 bluez 5.63-5 on CBL Mariner 2.0, azl3 bluez 5.63-6 on Azure Linux 3.0.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.