CVE-2024-45434

CRITICAL

OpenSynergy BlueSDK <6.x - Use After Free

Title source: llm
STIX 2.1

Description

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0593
EPSS Percentile 92.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-416
Status published
Products (1)
opensynergy/blue_sdk < 6.0.1
Published Sep 12, 2025
Tracked Since Feb 18, 2026