Microsoft Windows 10 Version 21H1 vulnerabilities

780 known vulnerabilities affecting microsoft/windows_10_version_21h1.

Total CVEs
780
CISA KEV
42
actively exploited
Public exploits
12
Exploited in wild
51
Severity breakdown
CRITICAL26HIGH586MEDIUM166LOW2

Vulnerabilities

Page 15 of 39
CVE-2022-30160HIGHCVSS 7.8≥ 10.0.0, < 10.0.19043.17662022-06-15
CVE-2022-30160 [HIGH] CVE-2022-30160: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-30131HIGHCVSS 7.8≥ 10.0.0, < 10.0.19043.17662022-06-15
CVE-2022-30131 [HIGH] CVE-2022-30131: Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-30146HIGHCVSS 7.5≥ 10.0.0, < 10.0.19043.17662022-06-15
CVE-2022-30146 [HIGH] CVE-2022-30146: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-30164HIGHCVSS 7.8≥ 10.0.0, < 10.0.19043.17662022-06-15
CVE-2022-30164 [HIGH] CVE-2022-30164: Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability
cvelistv5nvd
CVE-2022-30162MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19043.17662022-06-15
CVE-2022-30162 [MEDIUM] CVE-2022-30162: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
cvelistv5nvd
CVE-2022-30155MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19043.17662022-06-15
CVE-2022-30155 [MEDIUM] Windows Kernel Denial of Service Vulnerability Windows Kernel Denial of Service Vulnerability Windows Kernel Denial of Service Vulnerability
cvelistv5
CVE-2022-30148MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19043.17662022-06-15
CVE-2022-30148 [MEDIUM] CWE-532 CVE-2022-30148: Windows Desired State Configuration (DSC) Information Disclosure Vulnerability Windows Desired State Configuration (DSC) Information Disclosure Vulnerability
cvelistv5nvd
CVE-2022-30189MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19043.17662022-06-15
CVE-2022-30189 [MEDIUM] CVE-2022-30189: Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
cvelistv5nvd
CVE-2022-32230HIGHCVSS 7.5≥ 19042.1706, < 19042.1706≥ 19043.1706, < 19043.1706+1 more2022-06-14
CVE-2022-32230 [HIGH] CWE-476 CVE-2022-32230: Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the Windows kernel. For most systems, this attack requires authentication, except in
cvelistv5nvd
CVE-2022-30190HIGHCVSS 7.8KEVPoC≥ 10.0.0, < 10.0.19043.17662022-06-01
CVE-2022-30190 [HIGH] CVE-2022-30190: A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calli A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the cont
cvelistv5nvd
CVE-2022-30138HIGHCVSS 7.8≥ 10.0.0, < 10.0.19043.17062022-05-18
CVE-2022-30138 [HIGH] CVE-2022-30138: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-22012CRITICALCVSS 9.8≥ 10.0.0, < 10.0.19043.17062022-05-10
CVE-2022-22012 [CRITICAL] CVE-2022-22012: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-29130CRITICALCVSS 9.8≥ 10.0.0, < 10.0.19043.17062022-05-10
CVE-2022-29130 [CRITICAL] CVE-2022-29130: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-29125HIGHCVSS 7.0≥ 10.0.0, < 10.0.19043.17062022-05-10
CVE-2022-29125 [HIGH] CVE-2022-29125: Windows Push Notifications Apps Elevation of Privilege Vulnerability Windows Push Notifications Apps Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-26923HIGHCVSS 8.8KEVPoC≥ 10.0.0, < 10.0.19043.17062022-05-10
CVE-2022-26923 [HIGH] CWE-295 CVE-2022-26923: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-29137HIGHCVSS 8.8≥ 10.0.0, < 10.0.19043.17062022-05-10
CVE-2022-29137 [HIGH] CVE-2022-29137: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-22016HIGHCVSS 7.0≥ 10.0.0, < 10.0.19043.17062022-05-10
CVE-2022-22016 [HIGH] CVE-2022-22016: Windows PlayToManager Elevation of Privilege Vulnerability Windows PlayToManager Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-22013HIGHCVSS 8.8≥ 10.0.0, < 10.0.19043.17062022-05-10
CVE-2022-22013 [HIGH] CVE-2022-22013: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-29129HIGHCVSS 8.8≥ 10.0.0, < 10.0.19043.17062022-05-10
CVE-2022-29129 [HIGH] CVE-2022-29129: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-29103HIGHCVSS 7.8≥ 10.0.0, < 10.0.19043.17062022-05-10
CVE-2022-29103 [HIGH] CVE-2022-29103: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
cvelistv5nvd