March 28, 2022 · Applied Cybernetics Group
CVE-2010-4398 — Microsoft Windows
Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability
- Added to KEV
2022-03-28- Federal due date
2022-04-21- Vendor
- Microsoft
- Product
- Windows
- EPSS
- 92.1th percentile (score 0.077, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2010-4398
CISA short description
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
Required action
Apply updates per vendor instructions.