← Back to browse · API

CVE-2010-4398

Severity
HIGH
CVSS
7.8
EPSS
0.08661
Risk score
59.23
CISA KEV
Yes
PoC
No
Published
2022-03-28
Modified
2022-03-28
First seen
2026-08-07
Aliases
EUVD-2010-4367, GHSA-V6FX-3QCR-2MFG
Products
Microsoft:Windows, n/a:n/a n/a
Sources
euvd EUVD-2010-4367
cisa.gov CVE-2010-4398

Description

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.

References