CVE-2024-11857: Realtek Bluetooth Hci Adaptor

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by the link. Subsequently, attackers can leverage arbitrary file deletion to privilege escalation.

Affected products

  • Realtek Bluetooth Hci Adaptor: before 1.1.73.1 (fixed in 1.1.73.1)

Published 2025-06-02. Last modified 2026-06-17.