Microsoft Windows 10 21H2 vulnerabilities

1,584 known vulnerabilities affecting microsoft/windows_10_21h2.

Total CVEs
1,584
CISA KEV
86
actively exploited
Public exploits
31
Exploited in wild
55
Severity breakdown
CRITICAL39HIGH1118MEDIUM421LOW6

Vulnerabilities

Page 23 of 80
CVE-2025-49725HIGHCVSS 7.8fixed in 10.0.19044.60932025-07-08
CVE-2025-49725 [HIGH] CWE-416 CVE-2025-49725: Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47975HIGHCVSS 7.0fixed in 10.0.19044.60932025-07-08
CVE-2025-47975 [HIGH] CWE-415 CVE-2025-47975: Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48823MEDIUMCVSS 5.9fixed in 10.0.19044.60932025-07-08
CVE-2025-48823 [MEDIUM] CWE-310 CVE-2025-48823: Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose i Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-48808MEDIUMCVSS 5.5fixed in 10.0.19044.60932025-07-08
CVE-2025-48808 [MEDIUM] CWE-200 CVE-2025-48808: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-47980MEDIUMCVSS 6.2fixed in 10.0.19044.60932025-07-08
CVE-2025-47980 [MEDIUM] CWE-200 CVE-2025-47980: Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an un Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-48800MEDIUMCVSS 6.8fixed in 10.0.19044.60932025-07-08
CVE-2025-48800 [MEDIUM] CWE-693 CVE-2025-48800: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48811MEDIUMCVSS 6.7fixed in 10.0.19044.60932025-07-08
CVE-2025-48811 [MEDIUM] CWE-353 CVE-2025-48811: Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49664MEDIUMCVSS 5.5fixed in 10.0.19044.60932025-07-08
CVE-2025-49664 [MEDIUM] CWE-200 CVE-2025-49664: Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Hos Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose information locally.
nvd
CVE-2025-48003MEDIUMCVSS 6.8fixed in 10.0.19044.60932025-07-08
CVE-2025-48003 [MEDIUM] CWE-693 CVE-2025-48003: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48001MEDIUMCVSS 6.8fixed in 10.0.19044.60932025-07-08
CVE-2025-48001 [MEDIUM] CWE-367 CVE-2025-48001: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-49658MEDIUMCVSS 5.5fixed in 10.0.19044.60932025-07-08
CVE-2025-49658 [MEDIUM] CWE-125 CVE-2025-49658: Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
nvd
CVE-2025-48804MEDIUMCVSS 6.8fixed in 10.0.19044.60932025-07-08
CVE-2025-48804 [MEDIUM] CWE-349 CVE-2025-48804: Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorize Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48803MEDIUMCVSS 6.7fixed in 10.0.19044.60932025-07-08
CVE-2025-48803 [MEDIUM] CWE-353 CVE-2025-48803: Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49684MEDIUMCVSS 5.5fixed in 10.0.19044.60932025-07-08
CVE-2025-49684 [MEDIUM] CWE-126 CVE-2025-49684: Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locall Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-49722MEDIUMCVSS 5.7fixed in 10.0.19044.60932025-07-08
CVE-2025-49722 [MEDIUM] CWE-400 CVE-2025-49722: Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.
nvd
CVE-2025-48818MEDIUMCVSS 6.8fixed in 10.0.19044.60932025-07-08
CVE-2025-48818 [MEDIUM] CWE-367 CVE-2025-48818: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-47999MEDIUMCVSS 6.8fixed in 10.0.19044.60932025-07-08
CVE-2025-47999 [MEDIUM] CWE-820 CVE-2025-47999: Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adj Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
nvd
CVE-2025-49760LOWCVSS 3.5fixed in 10.0.19044.60932025-07-08
CVE-2025-49760 [LOW] CWE-73 CVE-2025-49760: External control of file name or path in Windows Storage allows an authorized attacker to perform sp External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2025-33073HIGHCVSS 8.8KEVPoCfixed in 10.0.19044.59652025-06-10
CVE-2025-33073 [HIGH] CWE-284 CVE-2025-33073: Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a ne Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2025-33070HIGHCVSS 8.1fixed in 10.0.19044.59652025-06-10
CVE-2025-33070 [HIGH] CWE-908 CVE-2025-33070: Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privile Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
nvd
Microsoft Windows 10 21H2 vulnerabilities | cvebase