← KEV catalog
CISA known exploited vulnerability

CVE-2010-4398

Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability

SOURCE FACT

Microsoft · Windows

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2010-4398

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?