Microsoft Windows 10 21H2 vulnerabilities
1,827 known vulnerabilities affecting microsoft/windows_10_21h2.
Total CVEs
1,827
CISA KEV
87
actively exploited
Public exploits
54
Exploited in wild
97
Severity breakdown
CRITICAL44HIGH1303MEDIUM473LOW7
Vulnerabilities
Page 74 of 92
CVE-2023-1018P4MEDIUMCVSS 5.5fixed in 10.0.19044.27282023-02-28
CVE-2023-1018 [MEDIUM] CWE-125 CVE-2023-1018: An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past th
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
nvd
CVE-2023-28222P4HIGHCVSS 7.1fixed in 10.0.19044.28462023-04-11
CVE-2023-28222 [HIGH] CWE-59 CVE-2023-28222: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-21356P4MEDIUMCVSS 6.5fixed in 10.0.19044.40462024-02-13
CVE-2024-21356 [MEDIUM] CWE-476 CVE-2024-21356: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2023-21739P4HIGHCVSS 7.0fixed in 10.0.19044.24862023-01-10
CVE-2023-21739 [HIGH] CWE-591 CVE-2023-21739: Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-36902P4HIGHCVSS 7.0fixed in 10.0.19041.35702023-10-10
CVE-2023-36902 [HIGH] CWE-416 CVE-2023-36902: Windows Runtime Remote Code Execution Vulnerability
Windows Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-28221P4HIGHCVSS 7.0fixed in 10.0.19044.28462023-04-11
CVE-2023-28221 [HIGH] CWE-200 CVE-2023-28221: Windows Error Reporting Service Elevation of Privilege Vulnerability
Windows Error Reporting Service Elevation of Privilege Vulnerability
nvd
CVE-2023-36721P4HIGHCVSS 7.0fixed in 10.0.19041.35702023-10-10
CVE-2023-36721 [HIGH] CWE-269 CVE-2023-36721: Windows Error Reporting Service Elevation of Privilege Vulnerability
Windows Error Reporting Service Elevation of Privilege Vulnerability
nvd
CVE-2024-21429P4MEDIUMCVSS 6.8fixed in 10.0.19044.41702024-03-12
CVE-2024-21429 [MEDIUM] CWE-197 CVE-2024-21429: Windows USB Hub Driver Remote Code Execution Vulnerability
Windows USB Hub Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21405P4HIGHCVSS 7.0fixed in 10.0.19044.40462024-02-13
CVE-2024-21405 [HIGH] CWE-591 CVE-2024-21405: Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
nvd
CVE-2023-29368P4HIGHCVSS 7.0fixed in 10.0.19044.30862023-06-14
CVE-2023-29368 [HIGH] CWE-415 CVE-2023-29368: Windows Filtering Platform Elevation of Privilege Vulnerability
Windows Filtering Platform Elevation of Privilege Vulnerability
nvd
CVE-2023-28216P4HIGHCVSS 7.0fixed in 10.0.19044.28462023-04-11
CVE-2023-28216 [HIGH] CVE-2023-28216: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2023-35378P4HIGHCVSS 7.0fixed in 10.0.19044.33242023-08-08
CVE-2023-35378 [HIGH] CWE-367 CVE-2023-35378: Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
nvd
CVE-2024-21355P4HIGHCVSS 7.0fixed in 10.0.19044.40462024-02-13
CVE-2024-21355 [HIGH] CWE-591 CVE-2024-21355: Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
nvd
CVE-2023-24861P4HIGHCVSS 7.0fixed in 10.0.19044.27282023-03-14
CVE-2023-24861 [HIGH] CWE-367 CVE-2023-24861: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-23393P4HIGHCVSS 7.0fixed in 10.0.19044.27282023-03-14
CVE-2023-23393 [HIGH] CWE-591 CVE-2023-23393: Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
nvd
CVE-2024-26252P4MEDIUMCVSS 6.8fixed in 10.0.19044.42912024-04-09
CVE-2024-26252 [MEDIUM] CWE-822 CVE-2024-26252: Windows rndismp6.sys Remote Code Execution Vulnerability
Windows rndismp6.sys Remote Code Execution Vulnerability
nvd
CVE-2024-26253P4MEDIUMCVSS 6.8fixed in 10.0.19044.42912024-04-09
CVE-2024-26253 [MEDIUM] CWE-20 CVE-2024-26253: Windows rndismp6.sys Remote Code Execution Vulnerability
Windows rndismp6.sys Remote Code Execution Vulnerability
nvd
CVE-2023-21694P4MEDIUMCVSS 6.8fixed in 10.0.19044.26042023-02-14
CVE-2023-21694 [MEDIUM] CWE-122 CVE-2023-21694: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2025-48800P4MEDIUMCVSS 6.8fixed in 10.0.19044.60932025-07-08
CVE-2025-48800 [MEDIUM] CWE-693 CVE-2025-48800: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48003P4MEDIUMCVSS 6.8fixed in 10.0.19044.60932025-07-08
CVE-2025-48003 [MEDIUM] CWE-693 CVE-2025-48003: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd