cbcvebase.

Microsoft Windows 10 21H2 vulnerabilities

1,827 known vulnerabilities affecting microsoft/windows_10_21h2.

Total CVEs
1,827
CISA KEV
87
actively exploited
Public exploits
54
Exploited in wild
97
Severity breakdown
CRITICAL44HIGH1303MEDIUM473LOW7

Vulnerabilities

Page 49 of 92
CVE-2026-48570P3HIGHCVSS 7.9fixed in 10.0.19044.74172026-06-09
CVE-2026-48570 [HIGH] CWE-693 CVE-2026-48570: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48568P3HIGHCVSS 7.9fixed in 10.0.19044.74172026-06-09
CVE-2026-48568 [HIGH] CWE-693 CVE-2026-48568: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-45588P3HIGHCVSS 7.9fixed in 10.0.19044.74172026-06-09
CVE-2026-45588 [HIGH] CWE-693 CVE-2026-45588: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48578P3HIGHCVSS 7.9fixed in 10.0.19044.74172026-06-09
CVE-2026-48578 [HIGH] CWE-284 CVE-2026-48578: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-47973P3HIGHCVSS 7.8fixed in 10.0.19044.60932025-07-08
CVE-2025-47973 [HIGH] CWE-126 CVE-2025-47973: Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges l Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-47971P3HIGHCVSS 7.8fixed in 10.0.19044.60932025-07-08
CVE-2025-47971 [HIGH] CWE-126 CVE-2025-47971: Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges l Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2024-49046P3HIGHCVSS 7.8fixed in 10.0.19044.51312024-11-12
CVE-2024-49046 [HIGH] CWE-367 CVE-2024-49046: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2025-21325P3HIGHCVSS 7.8fixed in 10.0.19044.53712025-01-17
CVE-2025-21325 [HIGH] CWE-732 CVE-2025-21325: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2025-54894P3HIGHCVSS 7.8fixed in 10.0.19044.63322025-09-09
CVE-2025-54894 [HIGH] CWE-122 CVE-2025-54894: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2023-29335P3HIGHCVSS 7.5fixed in 10.0.19044.29652023-05-09
CVE-2023-29335 [HIGH] CWE-20 CVE-2023-29335: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2023-21801P3HIGHCVSS 7.8fixed in 10.0.19044.26042023-02-14
CVE-2023-21801 [HIGH] CVE-2023-21801: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2024-26228P3HIGHCVSS 7.8fixed in 10.0.19044.42912024-04-09
CVE-2024-26228 [HIGH] CWE-310 CVE-2024-26228: Windows Cryptographic Services Security Feature Bypass Vulnerability Windows Cryptographic Services Security Feature Bypass Vulnerability
nvd
CVE-2025-47985P3HIGHCVSS 7.8fixed in 10.0.19044.60932025-07-08
CVE-2025-47985 [HIGH] CWE-822 CVE-2025-47985: Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate priv Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32071P3HIGHCVSS 7.5fixed in 10.0.19044.71842026-04-14
CVE-2026-32071 [HIGH] CWE-476 CVE-2026-32071: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-35416P3HIGHCVSS 7.0fixed in 10.0.19044.72912026-05-12
CVE-2026-35416 [HIGH] CWE-416 CVE-2026-35416: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29842P3HIGHCVSS 7.5fixed in 10.0.19044.58542025-05-13
CVE-2025-29842 [HIGH] CWE-349 CVE-2025-29842: Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-27908P3HIGHCVSS 7.0fixed in 10.0.19044.71842026-04-14
CVE-2026-27908 [HIGH] CWE-416 CVE-2026-27908: Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27738P3MEDIUMCVSS 6.5fixed in 10.0.19044.57372025-04-08
CVE-2025-27738 [MEDIUM] CWE-284 CVE-2025-27738: Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to dis Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-50159P3HIGHCVSS 7.3fixed in 10.0.19044.62162025-08-12
CVE-2025-50159 [HIGH] CWE-416 CVE-2025-50159: Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54116P3HIGHCVSS 7.3fixed in 10.0.19044.63322025-09-09
CVE-2025-54116 [HIGH] CWE-284 CVE-2025-54116: Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate priv Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.
nvd