Microsoft Windows 10 21H1 vulnerabilities

71 known vulnerabilities affecting microsoft/windows_10_21h1.

Total CVEs
71
CISA KEV
36
actively exploited
Public exploits
4
Exploited in wild
36
Severity breakdown
CRITICAL2HIGH52MEDIUM17

Vulnerabilities

Page 1 of 4
CVE-2024-38250HIGHCVSS 7.8fixed in 10.0.19044.48942024-09-10
CVE-2024-38250 [HIGH] CWE-126 CVE-2024-38250: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38252HIGHCVSS 7.8fixed in 10.0.19044.48942024-09-10
CVE-2024-38252 [HIGH] CWE-416 CVE-2024-38252: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-38257HIGHCVSS 7.5fixed in 10.0.19044.48942024-09-10
CVE-2024-38257 [HIGH] CWE-908 CVE-2024-38257: Microsoft AllJoyn API Information Disclosure Vulnerability Microsoft AllJoyn API Information Disclosure Vulnerability
nvd
CVE-2024-38119HIGHCVSS 7.5fixed in 10.0.19044.48942024-09-10
CVE-2024-38119 [HIGH] CWE-416 CVE-2024-38119: Windows Network Address Translation (NAT) Remote Code Execution Vulnerability Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
nvd
CVE-2024-38256MEDIUMCVSS 5.5fixed in 10.0.19044.48942024-09-10
CVE-2024-38256 [MEDIUM] CWE-908 CVE-2024-38256: Windows Kernel-Mode Driver Information Disclosure Vulnerability Windows Kernel-Mode Driver Information Disclosure Vulnerability
nvd
CVE-2024-38254MEDIUMCVSS 5.5fixed in 10.0.19044.48942024-09-10
CVE-2024-38254 [MEDIUM] CWE-908 CVE-2024-38254: Windows Authentication Information Disclosure Vulnerability Windows Authentication Information Disclosure Vulnerability
nvd
CVE-2024-30080CRITICALCVSS 9.8fixed in 10.0.19043.45292024-06-11
CVE-2024-30080 [CRITICAL] CWE-416 CVE-2024-30080: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-21420HIGHCVSS 8.8fixed in 10.0.19044.40462024-02-13
CVE-2024-21420 [HIGH] CWE-190 CVE-2024-21420: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21357HIGHCVSS 8.1fixed in 10.0.19044.40462024-02-13
CVE-2024-21357 [HIGH] CWE-843 CVE-2024-21357: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2022-44684MEDIUMCVSS 6.5fixed in 10.0.19043.23642023-12-20
CVE-2022-44684 [MEDIUM] CVE-2022-44684: Windows Local Session Manager (LSM) Denial of Service Vulnerability Windows Local Session Manager (LSM) Denial of Service Vulnerability
nvd
CVE-2023-36567HIGHCVSS 7.5fixed in 10.0.19041.35702023-10-10
CVE-2023-36567 [HIGH] CWE-908 CVE-2023-36567: Windows Deployment Services Information Disclosure Vulnerability Windows Deployment Services Information Disclosure Vulnerability
nvd
CVE-2023-36577HIGHCVSS 8.8fixed in 10.0.19041.35702023-10-10
CVE-2023-36577 [HIGH] CWE-122 CVE-2023-36577: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-36594HIGHCVSS 7.8fixed in 10.0.19041.35702023-10-10
CVE-2023-36594 [HIGH] CWE-843 CVE-2023-36594: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-36436HIGHCVSS 7.8fixed in 10.0.19041.35702023-10-10
CVE-2023-36436 [HIGH] CVE-2023-36436: Windows MSHTML Platform Remote Code Execution Vulnerability Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2023-36596HIGHCVSS 7.5fixed in 10.0.19041.35702023-10-10
CVE-2023-36596 [HIGH] CWE-822 CVE-2023-36596: Remote Procedure Call Information Disclosure Vulnerability Remote Procedure Call Information Disclosure Vulnerability
nvd
CVE-2023-36598HIGHCVSS 7.8fixed in 10.0.19041.35702023-10-10
CVE-2023-36598 [HIGH] CWE-122 CVE-2023-36598: Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2023-36585HIGHCVSS 7.5fixed in 10.0.19041.35702023-10-10
CVE-2023-36585 [HIGH] CWE-20 CVE-2023-36585: Windows upnphost.dll Denial of Service Vulnerability Windows upnphost.dll Denial of Service Vulnerability
nvd
CVE-2023-36584MEDIUMCVSS 5.4KEVfixed in 10.0.19041.35702023-10-10
CVE-2023-36584 [MEDIUM] CVE-2023-36584: Windows Mark of the Web Security Feature Bypass Vulnerability Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2023-36576MEDIUMCVSS 5.5fixed in 10.0.19041.35702023-10-10
CVE-2023-36576 [MEDIUM] CWE-190 CVE-2023-36576: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2022-35744CRITICALCVSS 9.8fixed in 10.0.19043.18892023-05-31
CVE-2022-35744 [CRITICAL] CVE-2022-35744: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd