Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 11 of 182
CVE-2026-69625P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69625 [HIGH] CWE-122 CVE-2026-69625: Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized
Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-36910P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36910 [CRITICAL] CWE-190 CVE-2023-36910: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-35385P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-35385 [CRITICAL] CWE-190 CVE-2023-35385: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38199P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38199 [CRITICAL] CWE-416 CVE-2024-38199: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2025-21307P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21307 [CRITICAL] CWE-416 CVE-2025-21307: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2026-69824P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69824 [CRITICAL] CWE-122 CVE-2026-69824: Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69496P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69496 [CRITICAL] CWE-122 CVE-2026-69496: Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69829P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69829 [CRITICAL] CWE-122 CVE-2026-69829: Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-70296P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70296 [CRITICAL] CWE-787 CVE-2026-70296: Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code ove
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49172P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49172 [CRITICAL] CWE-122 CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code ov
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-54995P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54995 [CRITICAL] CWE-416 CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-21746HIGHCVSS 7.8ExploitedPoC≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21746 [HIGH] Windows NTLM Elevation of Privilege Vulnerability
Windows NTLM Elevation of Privilege Vulnerability
Windows NTLM Elevation of Privilege Vulnerability
cvelistv5
CVE-2025-33064P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-33064 [HIGH] CWE-122 CVE-2025-33064: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-69628P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69628 [HIGH] CWE-122 CVE-2026-69628: Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a net
Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.
nvd
CVE-2026-72959P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72959 [HIGH] CWE-122 CVE-2026-72959: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
nvd
CVE-2026-56647P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56647 [HIGH] CWE-190 CVE-2026-56647: Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69681P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69681 [HIGH] CWE-122 CVE-2026-69681: Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69512P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69512 [HIGH] CWE-122 CVE-2026-69512: Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privile
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-32057P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-32057 [CRITICAL] CWE-20 CVE-2023-32057: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2022-21894MEDIUMCVSS 4.4ExploitedPoC≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21894 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
cvelistv5