cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 104 of 182
CVE-2026-69281P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69281 [HIGH] CWE-416 CVE-2026-69281: Use after free in Windows License Manager allows an authorized attacker to elevate privileges locall Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69331P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69331 [HIGH] CWE-416 CVE-2026-69331: Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-71342P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71342 [HIGH] CWE-416 CVE-2026-71342: Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-71333P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71333 [HIGH] CWE-416 CVE-2026-71333: Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-85360P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-85360 [HIGH] CWE-416 CVE-2026-85360: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69473P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69473 [HIGH] CWE-416 CVE-2026-69473: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32087P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32087 [HIGH] CWE-122 CVE-2026-32087: Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker t Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-73005P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73005 [HIGH] CWE-362 CVE-2026-73005: Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-30084P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.45292024-06-11
CVE-2024-30084 [HIGH] CWE-367 CVE-2024-30084: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-64670P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-64670 [MEDIUM] CWE-200 CVE-2025-64670: Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-34348P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-34348 [MEDIUM] CWE-693 CVE-2026-34348: Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to discl Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-69449P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69449 [MEDIUM] CWE-122 CVE-2026-69449: Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locall Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.
nvd
CVE-2026-71339P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71339 [MEDIUM] CWE-122 CVE-2026-71339: Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69820P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69820 [MEDIUM] CWE-122 CVE-2026-69820: Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges loca Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62801P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-62801 [MEDIUM] CWE-22 CVE-2026-62801: Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2024-26254P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.42912024-04-09
CVE-2024-26254 [HIGH] CWE-822 CVE-2024-26254: Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability
nvd
CVE-2021-43236P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43236 [HIGH] CVE-2021-43236: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2021-43222P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43222 [HIGH] CVE-2021-43222: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-21438P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-21438 [HIGH] CWE-369 CVE-2024-21438: Microsoft AllJoyn API Denial of Service Vulnerability Microsoft AllJoyn API Denial of Service Vulnerability
nvd
CVE-2025-21351P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21351 [HIGH] CWE-400 CVE-2025-21351: Windows Active Directory Domain Services API Denial of Service Vulnerability Windows Active Directory Domain Services API Denial of Service Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase