Microsoft Windows 10 Version 21H2 vulnerabilities
2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
124
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13
Vulnerabilities
Page 111 of 146
CVE-2023-23393P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23393 [HIGH] CWE-591 CVE-2023-23393: Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
nvd
CVE-2024-26252P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.42912024-04-09
CVE-2024-26252 [MEDIUM] CWE-822 CVE-2024-26252: Windows rndismp6.sys Remote Code Execution Vulnerability
Windows rndismp6.sys Remote Code Execution Vulnerability
nvd
CVE-2024-26253P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.42912024-04-09
CVE-2024-26253 [MEDIUM] CWE-20 CVE-2024-26253: Windows rndismp6.sys Remote Code Execution Vulnerability
Windows rndismp6.sys Remote Code Execution Vulnerability
nvd
CVE-2023-21694P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.26042023-02-14
CVE-2023-21694 [MEDIUM] CWE-122 CVE-2023-21694: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2026-50374P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50374 [MEDIUM] CWE-416 CVE-2026-50374: Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate pr
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.
nvd
CVE-2025-49743P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-49743 [MEDIUM] CWE-362 CVE-2025-49743: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29954P4MEDIUMCVSS 5.9≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29954 [MEDIUM] CWE-400 CVE-2025-29954: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-30034P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30034 [MEDIUM] CWE-843 CVE-2024-30034: Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
nvd
CVE-2025-29956P4MEDIUMCVSS 5.4≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29956 [MEDIUM] CWE-126 CVE-2025-29956: Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-25185P4MEDIUMCVSS 5.3≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25185 [MEDIUM] CWE-200 CVE-2026-25185: Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows a
Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-62567P4MEDIUMCVSS 5.3≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62567 [MEDIUM] CWE-191 CVE-2025-62567: Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny serv
Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.
nvd
CVE-2022-24460P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-24460 [HIGH] CVE-2022-24460: Tablet Windows User Interface Application Elevation of Privilege Vulnerability
Tablet Windows User Interface Application Elevation of Privilege Vulnerability
nvd
CVE-2022-29112P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-29112 [MEDIUM] CVE-2022-29112: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2023-21750P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21750 [HIGH] CWE-284 CVE-2023-21750: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-28222P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28222 [HIGH] CWE-59 CVE-2023-28222: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-28267P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28267 [MEDIUM] CWE-126 CVE-2023-28267: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2022-30225P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19043.18262022-07-12
CVE-2022-30225 [HIGH] CVE-2022-30225: Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
nvd
CVE-2022-29125P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-29125 [HIGH] CVE-2022-29125: Windows Push Notifications Apps Elevation of Privilege Vulnerability
Windows Push Notifications Apps Elevation of Privilege Vulnerability
nvd
CVE-2022-21867P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21867 [HIGH] CVE-2022-21867: Windows Push Notifications Apps Elevation of Privilege Vulnerability
Windows Push Notifications Apps Elevation of Privilege Vulnerability
nvd
CVE-2023-28224P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28224 [HIGH] CWE-591 CVE-2023-28224: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd