Vulnerability CVE-2014-4971


Published: 2014-07-26

Description:
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Microsoft XP SP3 BthPan.sys Arbitrary Write Privilege Escalation
Matt Bergin of K...
22.07.2014
Med.
Microsoft XP SP3 MQAC.sys Arbitrary Write Privilege Escalation
Matt Bergin of K...
22.07.2014
Med.
MQAC.sys Arbitrary Write Privilege Escalation
Spencer
25.07.2014
Med.
Microsoft Bluetooth Personal Area Networking Privilege Escalation
Jay Smith
16.10.2014

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

Vendor: Microsoft
Product: Windows xp 

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://blogs.technet.com/b/srd/archive/2014/10/14/accessing-risk-for-the-october-2014-security-updates.aspx
http://packetstormsecurity.com/files/127535/Microsoft-XP-SP3-BthPan.sys-Arbitrary-Write-Privilege-Escalation.html
http://packetstormsecurity.com/files/127536/Microsoft-XP-SP3-MQAC.sys-Arbitrary-Write-Privilege-Escalation.html
http://packetstormsecurity.com/files/128674/Microsoft-Bluetooth-Personal-Area-Networking-BthPan.sys-Privilege-Escalation.html
http://seclists.org/fulldisclosure/2014/Jul/96
http://seclists.org/fulldisclosure/2014/Jul/97
http://technet.microsoft.com/security/bulletin/MS14-062
http://www.exploit-db.com/exploits/34112
http://www.exploit-db.com/exploits/34131
http://www.exploit-db.com/exploits/34982
http://www.securityfocus.com/archive/1/archive/1/532843/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/532844/100/0/threaded
http://www.securityfocus.com/bid/68764
http://www.securitytracker.com/id/1031025
https://www.korelogic.com/Resources/Advisories/KL-001-2014-002.txt
https://www.korelogic.com/Resources/Advisories/KL-001-2014-003.txt

Related CVE
CVE-2018-8251
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media Foundation Memory Corruption Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, ...
CVE-2018-8233
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers.
CVE-2018-8225
A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Wind...
CVE-2018-8214
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 S...
CVE-2018-8210
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows ...
CVE-2018-8208
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 S...
CVE-2018-8207
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 200...
CVE-2018-8205
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Serve...

Copyright 2018, cxsecurity.com

 

Back to Top