Vulnerability CVE-2014-4971


Published: 2014-07-26

Description:
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Microsoft XP SP3 BthPan.sys Arbitrary Write Privilege Escalation
Matt Bergin of K...
22.07.2014
Med.
Microsoft XP SP3 MQAC.sys Arbitrary Write Privilege Escalation
Matt Bergin of K...
22.07.2014
Med.
MQAC.sys Arbitrary Write Privilege Escalation
Spencer
25.07.2014
Med.
Microsoft Bluetooth Personal Area Networking Privilege Escalation
Jay Smith
16.10.2014

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

Vendor: Microsoft
Product: Windows xp 

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://blogs.technet.com/b/srd/archive/2014/10/14/accessing-risk-for-the-october-2014-security-updates.aspx
http://packetstormsecurity.com/files/127535/Microsoft-XP-SP3-BthPan.sys-Arbitrary-Write-Privilege-Escalation.html
http://packetstormsecurity.com/files/127536/Microsoft-XP-SP3-MQAC.sys-Arbitrary-Write-Privilege-Escalation.html
http://packetstormsecurity.com/files/128674/Microsoft-Bluetooth-Personal-Area-Networking-BthPan.sys-Privilege-Escalation.html
http://seclists.org/fulldisclosure/2014/Jul/96
http://seclists.org/fulldisclosure/2014/Jul/97
http://technet.microsoft.com/security/bulletin/MS14-062
http://www.exploit-db.com/exploits/34112
http://www.exploit-db.com/exploits/34131
http://www.exploit-db.com/exploits/34982
http://www.securityfocus.com/archive/1/archive/1/532843/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/532844/100/0/threaded
http://www.securityfocus.com/bid/68764
http://www.securitytracker.com/id/1031025
https://www.korelogic.com/Resources/Advisories/KL-001-2014-002.txt
https://www.korelogic.com/Resources/Advisories/KL-001-2014-003.txt

Related CVE
CVE-2018-0862
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Re...
CVE-2018-0849
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Re...
CVE-2018-0848
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Re...
CVE-2018-0845
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Re...
CVE-2018-0819
Microsoft Office 2016 for Mac allows an attacker to send a specially crafted email attachment to a user in an attempt to launch a social engineering attack, such as phishing, due to how Outlook for Mac displays encoded email addresses, aka "Spoofing ...
CVE-2018-0818
Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, due to how the Chakra scripting engine handles accessing memory, aka "Scripting Engine Secu...
CVE-2018-0812
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Me...
CVE-2018-0807
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Re...

Copyright 2018, cxsecurity.com

 

Back to Top