← All CVEs

CVE-2014-4971

high · 7.2

Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.

7.2
CVSS
23.0%
EPSS (exploit prob.)
98th
EPSS percentile
2014-07-26
Published

AV:L/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-4971