CVE-2010-4398: Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
Other sources
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REGBINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4398?
CVE-2010-4398 has a severity rating that allows local users to gain privileges and bypass User Account Control.
How do I fix CVE-2010-4398?
To fix CVE-2010-4398, apply the latest security updates and patches provided by Microsoft for affected Windows versions.
What systems are affected by CVE-2010-4398?
CVE-2010-4398 affects multiple versions of Microsoft Windows, including Windows 7, Windows Vista, and Windows Server 2008.
Can CVE-2010-4398 be exploited remotely?
CVE-2010-4398 is a local privilege escalation vulnerability, meaning it cannot be exploited remotely without local access to the system.
Is there a workaround for CVE-2010-4398?
The primary mitigation for CVE-2010-4398 is to ensure that all security patches are applied, as no official workaround has been provided.