CVE-2014-4971
HIGH 7.2EPSS 23.0%
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.
- CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 23.05% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2014-07-26
- Updated
- 2024-08-06
Proof-of-concept exploits (3)
- http://www.exploit-db.com/exploits/34112
- http://www.exploit-db.com/exploits/34131
- http://www.exploit-db.com/exploits/34982
Metasploit modules (1)
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/34982
- https://www.exploit-db.com/exploits/34167
- https://www.exploit-db.com/exploits/34131
- https://www.exploit-db.com/exploits/34112