CVE-2014-4115

Microsoft Windows - Memory Corruption

Title source: llm
STIX 2.1

Description

fastfat.sys (aka the FASTFAT driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly allocate memory, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (reserved-memory write) by connecting a crafted USB device, aka "Microsoft Windows Disk Partition Driver Elevation of Privilege Vulnerability."

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70343
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60975

Scores

EPSS 0.0288
EPSS Percentile 85.5%

Details

CWE
CWE-399
Status published
Products (3)
microsoft/windows_server_2003
microsoft/windows_server_2008
microsoft/windows_vista
Published Oct 15, 2014
Tracked Since Feb 18, 2026