First published: Sat Jul 26 2014(Updated: )
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4971 is classified as a critical vulnerability due to its potential for privilege escalation.
To mitigate CVE-2014-4971, ensure that all applicable security updates and patches for Microsoft Windows XP SP3 are installed.
CVE-2014-4971 primarily affects local users of Microsoft Windows XP SP3 who can exploit the vulnerability to gain elevated privileges.
Exploitation of CVE-2014-4971 allows local users to write data to arbitrary memory locations, leading to potential system compromise.
Yes, CVE-2014-4971 remains relevant for organizations still using Windows XP SP3, as it poses significant security risks.