Pentest Limited is one of the foremost providers of IT security and penetration testing services in the UK and has a worldwide reputation for excellence.
Pentest Limited released a security alert for a vulnerability discovered in WIDCOMM Bluetooth Connectivity Software.
WIDCOMM's products provides a full range of Bluetooth connectivity solutions for PCs, PDAs, mobile phones, headsets, digital cameras, access points, and various output devices.
An unauthenticated remote attacker can submit various malformed service requests via Bluetooth, triggering a buffer overflow and executing arbitrary code on the vulnerable device.
On Windows platforms this allows arbitrary code execution under the context of the currently logged on user account.
Vulnerable Versions
WIDCOMM supply their Bluetooth Communications software to other companies to allow them to integrate Bluetooth technology into their devices. They also supply Bluetooth SDK's to enable developers to create applications that use Bluetooth. Therefore it may not be immediately apparent that you are using the WIDCOMM Bluetooth software and version numbers may vary.
You can read the full advisory here

Follow us on Twitter!