CVE-2014-4971

Published Jul 26, 2014

Last updated 6 years ago

Overview

Description
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.
Source
cve@mitre.org
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
7.2
Impact score
10
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-20

Evaluator

Comment
CWE-123: Write-what-where Condition <a href="http://cwe.mitre.org/data/definitions/123.html">CWE-123: Write-what-where Condition</a>
Impact
-
Solution
-

Configurations