Microsoft Windows 10 21H2 vulnerabilities
1,827 known vulnerabilities affecting microsoft/windows_10_21h2.
Total CVEs
1,827
CISA KEV
87
actively exploited
Public exploits
54
Exploited in wild
97
Severity breakdown
CRITICAL44HIGH1303MEDIUM473LOW7
Vulnerabilities
Page 39 of 92
CVE-2025-24046P3HIGHCVSS 7.8fixed in 10.0.19044.56082025-03-11
CVE-2025-24046 [HIGH] CWE-416 CVE-2025-24046: Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges lo
Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49667P3HIGHCVSS 7.8fixed in 10.0.19044.60932025-07-08
CVE-2025-49667 [HIGH] CWE-415 CVE-2025-49667: Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49721P3HIGHCVSS 7.8fixed in 10.0.19044.60932025-07-08
CVE-2025-49721 [HIGH] CWE-122 CVE-2025-49721: Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate pri
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-20832P3HIGHCVSS 7.8fixed in 10.0.19044.68092026-01-13
CVE-2026-20832 [HIGH] CWE-415 CVE-2026-20832: Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerabili
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
nvd
CVE-2026-20857P3HIGHCVSS 7.8fixed in 10.0.19044.68092026-01-13
CVE-2026-20857 [HIGH] CWE-822 CVE-2026-20857: Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacke
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53800P3HIGHCVSS 7.8fixed in 10.0.19044.63322025-09-09
CVE-2025-53800 [HIGH] CWE-1419 CVE-2025-53800: No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privi
No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-32712P3HIGHCVSS 7.8fixed in 10.0.19044.59652025-06-10
CVE-2025-32712 [HIGH] CWE-416 CVE-2025-32712: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54091P3HIGHCVSS 7.8fixed in 10.0.19044.63322025-09-09
CVE-2025-54091 [HIGH] CWE-122 CVE-2025-54091: Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privilege
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48820P3HIGHCVSS 7.8fixed in 10.0.19044.60932025-07-08
CVE-2025-48820 [HIGH] CWE-59 CVE-2025-48820: Improper link resolution before file access ('link following') in Windows AppX Deployment Service al
Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33838P3HIGHCVSS 7.8fixed in 10.0.19044.72912026-05-12
CVE-2026-33838 [HIGH] CWE-415 CVE-2026-33838: Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20822P3HIGHCVSS 7.8fixed in 10.0.19044.68092026-01-13
CVE-2026-20822 [HIGH] CWE-416 CVE-2026-20822: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59207P3HIGHCVSS 7.8fixed in 10.0.19044.64562025-10-14
CVE-2025-59207 [HIGH] CWE-20 CVE-2025-59207: Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23673P3HIGHCVSS 7.8fixed in 10.0.19044.70582026-03-10
CVE-2026-23673 [HIGH] CWE-125 CVE-2026-23673: Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47976P3HIGHCVSS 7.8fixed in 10.0.19044.60932025-07-08
CVE-2025-47976 [HIGH] CWE-416 CVE-2025-47976: Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55701P3HIGHCVSS 7.8fixed in 10.0.19044.64562025-10-14
CVE-2025-55701 [HIGH] CWE-1287 CVE-2025-55701: Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50170P3HIGHCVSS 7.8fixed in 10.0.19044.62162025-08-12
CVE-2025-50170 [HIGH] CWE-280 CVE-2025-50170: Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Drive
Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47982P3HIGHCVSS 7.8fixed in 10.0.19044.60932025-07-08
CVE-2025-47982 [HIGH] CWE-20 CVE-2025-47982: Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate pri
Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62462P3HIGHCVSS 7.8fixed in 10.0.19044.66912025-12-09
CVE-2025-62462 [HIGH] CWE-126 CVE-2025-62462: Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privilege
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62457P3HIGHCVSS 7.8fixed in 10.0.19044.66912025-12-09
CVE-2025-62457 [HIGH] CWE-125 CVE-2025-62457: Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevat
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62464P3HIGHCVSS 7.8fixed in 10.0.19044.66912025-12-09
CVE-2025-62464 [HIGH] CWE-126 CVE-2025-62464: Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privilege
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd