CVE-2014-4971

high

Description

Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.

References

https://www.korelogic.com/Resources/Advisories/KL-001-2014-003.txt

https://www.korelogic.com/Resources/Advisories/KL-001-2014-002.txt

https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-4886

https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-062

http://www.securitytracker.com/id/1031025

http://www.securityfocus.com/bid/68764

http://www.securityfocus.com/archive/1/532844/100/0/threaded

http://www.securityfocus.com/archive/1/532843/100/0/threaded

http://www.osvdb.org/109387

http://www.exploit-db.com/exploits/34982

http://www.exploit-db.com/exploits/34131

http://www.exploit-db.com/exploits/34112

http://secunia.com/advisories/60974

http://seclists.org/fulldisclosure/2014/Jul/97

http://seclists.org/fulldisclosure/2014/Jul/96

http://packetstormsecurity.com/files/128674/Microsoft-Bluetooth-Personal-Area-Networking-BthPan.sys-Privilege-Escalation.html

http://packetstormsecurity.com/files/127536/Microsoft-XP-SP3-MQAC.sys-Arbitrary-Write-Privilege-Escalation.html

http://packetstormsecurity.com/files/127535/Microsoft-XP-SP3-BthPan.sys-Arbitrary-Write-Privilege-Escalation.html

http://blogs.technet.com/b/srd/archive/2014/10/14/accessing-risk-for-the-october-2014-security-updates.aspx

Details

Source: Mitre, NVD

Published: 2014-07-26

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.1516