CVE-2014-4971

Microsoft Windows XP SP3 - Privilege Escalation

Title source: llm

Description

Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows_x86
https://www.exploit-db.com/exploits/34982
exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows_x86
https://www.exploit-db.com/exploits/34167
exploitdb WORKING POC
by KoreLogic · pythonlocalwindows
https://www.exploit-db.com/exploits/34131
exploitdb WORKING POC
by KoreLogic · textlocalwindows
https://www.exploit-db.com/exploits/34112
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bthpan.rb
metasploit WORKING POC NORMAL
by Matt Bergin, Spencer McIntyre · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/mqac_write.rb

References (18)

Scores

EPSS 0.1867
EPSS Percentile 95.3%

Details

CWE
CWE-20
Status published
Products (1)
microsoft/windows_xp
Published Jul 26, 2014
Tracked Since Feb 18, 2026