Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-4398

76
FAUCET Score

CVE-2010-4398 describes a stack-based buffer overflow in the RtlQueryRegistryValues function within win32k.sys, affecting multiple versions of Microsoft Windows, including XP, Vista, Server 2003, Server 2008, and Windows 7. This vulnerability allows a local attacker to gain elevated privileges and bypass User Account Control (UAC) by manipulating a specific registry key with a crafted REG_BINARY value. With a CVSS score of 7.8 (High), it represents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. This CVE is listed in CISA's KEV catalog, indicating active exploitation, and publicly available exploit code exists on ExploitDB, alongside notable community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
r2CPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
8.66%
Probability of exploitation in next 30 days
EPSS Percentile
94.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Added to KEV · Mar 28, 2022
ExploitDB: EDB-15609 · Nov 24, 2010
This CVE's current EPSS score of 0.0866 is in the 99th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
isc.sans.edu / diary.html
ExploitIssue Tracking
nakedsecurity.sophos.com / 2010/11/25/new-windows-zero-day-flaw-bypasses-uac
Broken Link
docs.microsoft.com / en-us/security-updates/securitybulletins/2011/ms11-011
PatchVendor Advisory
secunia.com / advisories/42356
Broken LinkVendor Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12162
Broken Link
support.avaya.com / css/P8/documents/100127248
Third Party Advisory
twitter.com / msftsecresponse/statuses/7590788200402945
Not Applicable
exploit-db.com / bypassing-uac-with-user-privilege-under-windows-vista7-mirror
Broken LinkExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/15609
ExploitThird Party AdvisoryVDB Entry
kb.cert.org / vuls/id/529673
Third Party AdvisoryUS Government Resource
securityfocus.com / bid/45045
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
vupen.com / english/advisories/2011/0324
Broken Link