CISA Known Exploited Vulnerability

CVE-2010-4398

Microsoft · Windows

Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability

Date added
BOD 22-01 due date
CWE CWE-119
Ransomware Unknown

CISA description

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.

Required action

Apply updates per vendor instructions.