Microsoft Windows 10 Version 21H2 vulnerabilities
2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
124
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13
Vulnerabilities
Page 106 of 146
CVE-2025-54915P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54915 [MEDIUM] CWE-843 CVE-2025-54915: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54109P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54109 [MEDIUM] CWE-843 CVE-2025-54109: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53808P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-53808 [MEDIUM] CWE-843 CVE-2025-53808: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53810P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-53810 [MEDIUM] CWE-843 CVE-2025-53810: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54094P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54094 [MEDIUM] CWE-843 CVE-2025-54094: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-0390P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-0390 [MEDIUM] CWE-807 CVE-2026-0390: Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized atta
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-21265P4MEDIUMCVSS 6.4≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-21265 [MEDIUM] CWE-1329 CVE-2026-21265: Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificate
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot.
The ope
nvd
CVE-2026-49804P3MEDIUMCVSS 6.6≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49804 [MEDIUM] CWE-122 CVE-2026-49804: Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate pr
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-49174P3MEDIUMCVSS 6.1≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49174 [MEDIUM] CWE-306 CVE-2026-49174: Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
nvd
CVE-2025-21419P4HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21419 [HIGH] CWE-59 CVE-2025-21419: Windows Setup Files Cleanup Elevation of Privilege Vulnerability
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
nvd
CVE-2024-30033P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30033 [HIGH] CWE-59 CVE-2024-30033: Windows Search Service Elevation of Privilege Vulnerability
Windows Search Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21865P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21865 [HIGH] CVE-2022-21865: Connected Devices Platform Service Elevation of Privilege Vulnerability
Connected Devices Platform Service Elevation of Privilege Vulnerability
nvd
CVE-2024-21432P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-21432 [HIGH] CWE-59 CVE-2024-21432: Windows Update Stack Elevation of Privilege Vulnerability
Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2022-21967P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-21967 [HIGH] CVE-2022-21967: Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
nvd
CVE-2022-21862P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21862 [HIGH] CVE-2022-21862: Windows Application Model Core API Elevation of Privilege Vulnerability
Windows Application Model Core API Elevation of Privilege Vulnerability
nvd
CVE-2025-21349P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21349 [MEDIUM] CWE-287 CVE-2025-21349: Windows Remote Desktop Configuration Service Tampering Vulnerability
Windows Remote Desktop Configuration Service Tampering Vulnerability
nvd
CVE-2025-21414P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21414 [HIGH] CWE-122 CVE-2025-21414: Windows Core Messaging Elevation of Privileges Vulnerability
Windows Core Messaging Elevation of Privileges Vulnerability
nvd
CVE-2025-21184P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21184 [HIGH] CWE-122 CVE-2025-21184: Windows Core Messaging Elevation of Privileges Vulnerability
Windows Core Messaging Elevation of Privileges Vulnerability
nvd
CVE-2024-38248P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.48942024-09-10
CVE-2024-38248 [HIGH] CWE-416 CVE-2024-38248: Windows Storage Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2024-21445P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-21445 [HIGH] CWE-415 CVE-2024-21445: Windows USB Print Driver Elevation of Privilege Vulnerability
Windows USB Print Driver Elevation of Privilege Vulnerability
nvd