Microsoft Windows 10 Version 21H2 vulnerabilities
2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
124
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13
Vulnerabilities
Page 104 of 146
CVE-2022-21864P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21864 [HIGH] CVE-2022-21864: Windows UI Immersive Server API Elevation of Privilege Vulnerability
Windows UI Immersive Server API Elevation of Privilege Vulnerability
nvd
CVE-2022-21860P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21860 [HIGH] CVE-2022-21860: Windows AppContracts API Server Elevation of Privilege Vulnerability
Windows AppContracts API Server Elevation of Privilege Vulnerability
nvd
CVE-2024-20664P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20664 [MEDIUM] CWE-822 CVE-2024-20664: Microsoft Message Queuing Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-20663P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20663 [MEDIUM] CWE-822 CVE-2024-20663: Windows Message Queuing Client (MSMQC) Information Disclosure
Windows Message Queuing Client (MSMQC) Information Disclosure
nvd
CVE-2022-23298P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability
Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38022P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38022 [HIGH] CWE-59 CVE-2024-38022: Windows Image Acquisition Elevation of Privilege Vulnerability
Windows Image Acquisition Elevation of Privilege Vulnerability
nvd
CVE-2023-36403P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19043.36932023-11-14
CVE-2023-36403 [HIGH] CWE-591 CVE-2023-36403: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43535P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43535 [HIGH] CWE-416 CVE-2024-43535: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43570P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43570 [HIGH] CWE-416 CVE-2024-43570: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2026-49165P4HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49165 [HIGH] CWE-908 CVE-2026-49165: Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclo
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
nvd
CVE-2024-49084P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49084 [HIGH] CWE-362 CVE-2024-49084: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38136P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38136 [HIGH] CWE-416 CVE-2024-38136: Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
nvd
CVE-2024-38137P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38137 [HIGH] CWE-416 CVE-2024-38137: Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
nvd
CVE-2024-43511P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.51312024-10-08
CVE-2024-43511 [HIGH] CWE-367 CVE-2024-43511: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-29364P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.30862023-06-14
CVE-2023-29364 [HIGH] CWE-190 CVE-2023-29364: Windows Authentication Elevation of Privilege Vulnerability
Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2024-38069P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38069 [HIGH] CWE-347 CVE-2024-38069: Windows Enroll Engine Security Feature Bypass Vulnerability
Windows Enroll Engine Security Feature Bypass Vulnerability
nvd
CVE-2025-49685P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49685 [HIGH] CWE-416 CVE-2025-49685: Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privil
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21191P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-21191 [HIGH] CWE-367 CVE-2025-21191: Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows a
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-38033P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-38033 [MEDIUM] CVE-2022-38033: Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
nvd
CVE-2025-21301P4MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21301 [MEDIUM] CWE-284 CVE-2025-21301: Windows Geolocation Service Information Disclosure Vulnerability
Windows Geolocation Service Information Disclosure Vulnerability
nvd