CVE-2014-4971
Microsoft Windows XP SP3 - Privilege Escalation
Title source: llmDescription
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.
Exploits (6)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalwindows_x86
https://www.exploit-db.com/exploits/34982
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalwindows_x86
https://www.exploit-db.com/exploits/34167
metasploit
WORKING POC
NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bthpan.rb
metasploit
WORKING POC
NORMAL
by Matt Bergin, Spencer McIntyre · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/mqac_write.rb
References (18)
Scores
EPSS
0.1867
EPSS Percentile
95.3%
Details
CWE
CWE-20
Status
published
Products (1)
microsoft/windows_xp
Published
Jul 26, 2014
Tracked Since
Feb 18, 2026