CVE-2014-4971
CVE-2014-4971
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.
Productos afectados
n/a · n/aPoCs públicas encontradas — 10
cve_referencepacketstormsecurity.com/files/127535/Microsoft-XP-SP3-BthPan.sys-Arbitrary-Write-Privilege-Escalation.htmlno verificadocve_referencepacketstormsecurity.com/files/127536/Microsoft-XP-SP3-MQAC.sys-Arbitrary-Write-Privilege-Escalation.htmlno verificadocve_referencepacketstormsecurity.com/files/128674/Microsoft-Bluetooth-Personal-Area-Networking-BthPan.sys-Privilege-Escalation.htmlno verificadocve_referencewww.exploit-db.com/exploits/34112no verificadocve_referencewww.exploit-db.com/exploits/34131no verificadocve_referencewww.exploit-db.com/exploits/34982no verificadoexploitdbwww.exploit-db.com/exploits/34131no verificadoexploitdbwww.exploit-db.com/exploits/34112no verificadoexploitdbwww.exploit-db.com/exploits/34982no verificadoexploitdbwww.exploit-db.com/exploits/34167no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://blogs.technet.com/b/srd/archive/2014/10/14/accessing-risk-for-the-october-2014-security-updates.aspxhttp://packetstormsecurity.com/files/127535/Microsoft-XP-SP3-BthPan.sys-Arbitrary-Write-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/127536/Microsoft-XP-SP3-MQAC.sys-Arbitrary-Write-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/128674/Microsoft-Bluetooth-Personal-Area-Networking-BthPan.sys-Privilege-Escalation.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-062http://seclists.org/fulldisclosure/2014/Jul/96http://seclists.org/fulldisclosure/2014/Jul/97http://secunia.com/advisories/60974https://www.korelogic.com/Resources/Advisories/KL-001-2014-002.txthttps://www.korelogic.com/Resources/Advisories/KL-001-2014-003.txthttp://www.exploit-db.com/exploits/34112http://www.exploit-db.com/exploits/34131