CVE-2014-4971
26.07.2014, 15:55
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.Enginsight
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_xp | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References