Microsoft Windows 10 21H2 vulnerabilities

1,584 known vulnerabilities affecting microsoft/windows_10_21h2.

Total CVEs
1,584
CISA KEV
86
actively exploited
Public exploits
31
Exploited in wild
55
Severity breakdown
CRITICAL39HIGH1118MEDIUM421LOW6

Vulnerabilities

Page 34 of 80
CVE-2025-21224HIGHCVSS 8.1fixed in 10.0.19044.53712025-01-14
CVE-2025-21224 [HIGH] CWE-416 CVE-2025-21224: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2025-21334HIGHCVSS 7.8KEVfixed in 10.0.19044.53712025-01-14
CVE-2025-21334 [HIGH] CWE-416 CVE-2025-21334: Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
nvd
CVE-2025-21289HIGHCVSS 7.5fixed in 10.0.19044.53712025-01-14
CVE-2025-21289 [HIGH] CWE-400 CVE-2025-21289: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21389HIGHCVSS 7.5fixed in 10.0.19044.53712025-01-14
CVE-2025-21389 [HIGH] CWE-400 CVE-2025-21389: Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an un Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21295HIGHCVSS 8.1fixed in 10.0.19044.53712025-01-14
CVE-2025-21295 [HIGH] CWE-416 CVE-2025-21295: SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
nvd
CVE-2025-21302HIGHCVSS 8.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21302 [HIGH] CWE-122 CVE-2025-21302: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21294HIGHCVSS 8.1fixed in 10.0.19044.53712025-01-14
CVE-2025-21294 [HIGH] CWE-591 CVE-2025-21294: Microsoft Digest Authentication Remote Code Execution Vulnerability Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2025-21332HIGHCVSS 8.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21332 [HIGH] CWE-41 CVE-2025-21332: MapUrlToZone Security Feature Bypass Vulnerability MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21292HIGHCVSS 8.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21292 [HIGH] CWE-94 CVE-2025-21292: Windows Search Service Elevation of Privilege Vulnerability Windows Search Service Elevation of Privilege Vulnerability
nvd
CVE-2025-21305HIGHCVSS 8.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21305 [HIGH] CWE-122 CVE-2025-21305: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21252HIGHCVSS 8.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21252 [HIGH] CWE-122 CVE-2025-21252: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21235HIGHCVSS 7.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21235 [HIGH] CWE-20 CVE-2025-21235: Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
nvd
CVE-2025-21382HIGHCVSS 7.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21382 [HIGH] CWE-122 CVE-2025-21382: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2025-21266HIGHCVSS 8.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21266 [HIGH] CWE-122 CVE-2025-21266: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21230HIGHCVSS 7.5fixed in 10.0.19044.53712025-01-14
CVE-2025-21230 [HIGH] CWE-20 CVE-2025-21230: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21276HIGHCVSS 7.5fixed in 10.0.19044.53712025-01-14
CVE-2025-21276 [HIGH] CWE-191 CVE-2025-21276: Windows MapUrlToZone Denial of Service Vulnerability Windows MapUrlToZone Denial of Service Vulnerability
nvd
CVE-2025-21277HIGHCVSS 7.5fixed in 10.0.19044.53712025-01-14
CVE-2025-21277 [HIGH] CWE-126 CVE-2025-21277: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21240HIGHCVSS 8.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21240 [HIGH] CWE-122 CVE-2025-21240: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21411HIGHCVSS 8.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21411 [HIGH] CWE-122 CVE-2025-21411: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21237HIGHCVSS 8.8fixed in 10.0.19044.53712025-01-14
CVE-2025-21237 [HIGH] CWE-122 CVE-2025-21237: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd