CVE-2010-4398CISA KEV
Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
- Product
- Windows
- Added to KEV
- 28 Mar 2022
- Federal remediation due
- 21 Apr 2022
- Known ransomware use
- Not reported