Junglewise Threat Intelligence

CVE-2010-4398: Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability

CVE-2010-4398 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Windows, Microsoft Windows Server 2003, Microsoft Windows Vista, Microsoft Windows XP, Microsoft Windows Server 2008, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

A stack-based buffer overflow vulnerability exists in the RtlQueryRegistryValues function in win32k.sys. Local attackers can exploit this via a crafted REG_BINARY value for the SystemDefaultEUDCFont registry key to gain elevated privileges and bypass User Account Control (UAC).

Affected products

  • Microsoft Windows XP SP2, SP3
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista SP1, SP2
  • Microsoft Windows Server 2008 Gold, SP2, R2
  • Microsoft Windows 7

Timeline

  • 2010-11-25: disclosed: Initial reports of zero-day flaw bypassing UAC
  • 2011-02-08: patched: Microsoft released security bulletin MS11-011
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-28: advisory: NVD publication date

Related threats