A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2010-4398

Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability

Published
2022-03-28
Modified
2026-07-31
Sources
cisa-kev

Summary

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.