CVE-2024-11857
Severity CVSS v4.0:
HIGH
Type:
CWE-59
Link Following
Publication date:
02/06/2025
Last modified:
02/06/2025
Description
Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by the link. Subsequently, attackers can leverage arbitrary file deletion to privilege escalation.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH