A vulnerability was discovered in Toshiba's Bluetooth Stack for Windows and Service Station and can be used by attackers to gain privileges on a computer.

With elevated privileges on the machine, a malicious user has the ability to take control of the computer by executing malicious programs, modifying or deleting information stored on the hard drive.
The vulnerability has been assigned the identifier CVE-2015-0884 and is a privilege escalation vulnerability, with a CVSS score of 5.3, according to information from the Computer Emergency Response Team (CERT) at Carnegie Mellon University.
Successful exploitation requires local authentication, which makes it more difficult to compromise the system. Giovanni Delvecchio from SMARTnet is credited with discovering the vulnerability.
Toshiba has released updates for the affected products and urges users to apply them immediately. The software versions that resolve the security issue are 10.09.32 for the Bluetooth Stack for Windows and 2.2.14 for the Service Station.
In a security advisory, the company offers instructions on how a user can determine if the version of the software they have installed is vulnerable and how to apply the update. The new releases are available from Toshiba.
The company warns that if the Bluetooth Stack for Windows is not pre-installed on the machine, it may be added with the software associated with the Bluetooth adapter.
