CVE-2024-11857

Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by the link. Subsequently, attackers can leverage arbitrary file deletion to privilege escalation.
Configurations

No configuration.

History

02 Jun 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-02 04:15

Updated : 2025-06-02 17:32


NVD link : CVE-2024-11857

Mitre link : CVE-2024-11857

CVE.ORG link : CVE-2024-11857


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')