CVE-2014-4971 is a privilege escalation vulnerability in the MQAC.sys driver (version 5.1.0.1110) on Microsoft Windows XP SP3. The flaw is a write-what-where condition in the IRP handler routines, allowing a local attacker to write arbitrary data to any location in kernel memory by issuing a crafted IOCTL call. Exploitation typically involves overwriting the HalDispatchTable+0x4 pointer and triggering code execution via NtQueryIntervalProfile, resulting in SYSTEM-level privileges. The vulnerability was discovered by Matt Bergin of KoreLogic Security and publicly disclosed after Microsoft declined to patch it due to end of support for Windows XP.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module (bthpan.rb) that exploits a local privilege escalation vulnerability (CVE-2014-4971, MS14-062) in the Microsoft Bluetooth Personal Area Networking (BthPan.sys) driver on Windows XP SP3. The exploit works by opening a handle to the \\.\bthpan device, disclosing kernel addresses (HalDispatchTable and hal.dll base), and injecting custom shellcode into kernel memory. The shellcode performs token stealing to grant SYSTEM privileges to the current process. After successful privilege escalation, the module executes a user-supplied payload (typically Meterpreter shellcode) with SYSTEM privileges. The exploit is operational and requires local access to a vulnerable system. The only fingerprintable endpoints are the device path (\\.\bthpan) and the hal.dll kernel module. The code is written in Ruby and is designed to be run within the Metasploit Framework.
This repository contains a single Metasploit module (mqac_write.rb) that exploits a local privilege escalation vulnerability in the MQAC.sys driver on Windows XP SP3 (CVE-2014-4971). The exploit leverages an arbitrary kernel memory write to elevate the current session to SYSTEM privileges. It then injects a Meterpreter payload into another SYSTEM process, granting the attacker full control at the highest privilege level. The module is written in Ruby and is designed to be used within the Metasploit Framework. The main fingerprintable endpoint is the device handle \\.\MQAC, which is used to interact with the vulnerable driver. The exploit is operational and requires a Meterpreter session on a 32-bit Windows XP SP3 system with the MQAC.sys driver present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.