CVE-2026-35553Disclosure

LOWCVSS 8.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-13: 2Technical Details · 2026-04-13: 204-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Mr.Rabbit@01ra66it
    Disclosure

    【Dynabook製Bluetooth ACPIドライバーにおけるスタックベースのバッファオーバーフローの脆弱性】 JVNは4/13、Dynabook製Bluetooth ACPIドライバーにスタックベースのバッファオーバーフロー脆弱性があると公表しました。対象は TOSRFEC.SYS の全バージョンと DRFEC.SYS v11.0.0.0 以前で、CVE は CVE-2026-35553 です。 この脆弱性は外部公開サーバ向けではなく端末側のドライバ層で、攻撃には高権限や特定条件が必要です。ただ、日本国内で長く使われてきたブランドの端末が対象となり得るため、“古いけれど現役”の社内PCが見落としポイントになります。 攻撃者にとっては、端末侵害後の持続化や追加実行の足場として使える可能性があり、ローカル権限前提だから安全とは言い切れません。日本側では、対象端末の洗い出しとドライバ版数確認を早めに済ませたい案件です。 #JVN #Dynabook #CVE202635553 #ドライバ脆弱性 #端末管理 https://jvn.jp/vu/JVNVU96334293/index.html

    Post summary

    Japanese security firm JVN disclosed a stack‑based buffer overflow in Dynabook’s Bluetooth ACPI driver (CVE‑2026‑35553), detailing affected driver versions and privilege requirements, but no PoC, exploit code, active exploitation, or patch information is provided.

    00000366
    3.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35553 Stack-Based Buffer Overflow in Dynabook Inc. Bluetooth ACPI Drivers https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35553

    Post summary

    The snippet provides a concise disclosure of CVE-2026-35553, noting it is a stack-based buffer overflow in Dynabook’s Bluetooth ACPI drivers, with no additional exploitation or mitigation details.

    0000063
    4.0K followersView on X

Explore more