Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-4398
Description:Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-4398
BugTraq ID: 45045
http://www.securityfocus.com/bid/45045
CERT/CC vulnerability note: VU#529673
http://www.kb.cert.org/vuls/id/529673
http://www.exploit-db.com/exploits/15609/
http://isc.sans.edu/diary.html?storyid=9988
http://nakedsecurity.sophos.com/2010/11/25/new-windows-zero-day-flaw-bypasses-uac/
http://twitter.com/msftsecresponse/statuses/7590788200402945
http://www.exploit-db.com/bypassing-uac-with-user-privilege-under-windows-vista7-mirror/
Microsoft Security Bulletin: MS11-011
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-011
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12162
http://www.securitytracker.com/id?1025046
http://secunia.com/advisories/42356
http://www.vupen.com/english/advisories/2011/0324




© 1998-2025 E-Soft Inc. All rights reserved.