cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
124
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13

Vulnerabilities

Page 112 of 146
CVE-2023-23407P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23407 [HIGH] CWE-591 CVE-2023-23407: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2023-23414P4HIGHCVSS 7.1≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23414 [HIGH] CWE-591 CVE-2023-23414: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2022-21896P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21896 [HIGH] CWE-362 CVE-2022-21896: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-23288P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-23288 [HIGH] CVE-2022-23288: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2023-35329P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35329 [MEDIUM] CWE-400 CVE-2023-35329: Windows Authentication Denial of Service Vulnerability Windows Authentication Denial of Service Vulnerability
nvd
CVE-2022-24525P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19043.15862022-03-09
CVE-2022-24525 [HIGH] CWE-362 CVE-2022-24525: Windows Update Stack Elevation of Privilege Vulnerability Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2024-43534P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43534 [MEDIUM] CWE-125 CVE-2024-43534: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-38027P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-38027 [HIGH] CWE-362 CVE-2022-38027: Windows Storage Elevation of Privilege Vulnerability Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2023-29368P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.30862023-06-14
CVE-2023-29368 [HIGH] CWE-415 CVE-2023-29368: Windows Filtering Platform Elevation of Privilege Vulnerability Windows Filtering Platform Elevation of Privilege Vulnerability
nvd
CVE-2023-28216P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28216 [HIGH] CVE-2023-28216: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2022-26828P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-26828 [HIGH] CWE-362 CVE-2022-26828: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-23385P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23385 [HIGH] CWE-190 CVE-2023-23385: Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
nvd
CVE-2022-26807P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-26807 [HIGH] CWE-362 CVE-2022-26807: Windows Work Folder Service Elevation of Privilege Vulnerability Windows Work Folder Service Elevation of Privilege Vulnerability
nvd
CVE-2022-44669P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.23642022-12-13
CVE-2022-44669 [HIGH] CWE-362 CVE-2022-44669: Windows Error Reporting Elevation of Privilege Vulnerability Windows Error Reporting Elevation of Privilege Vulnerability
nvd
CVE-2023-21733P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21733 [HIGH] CWE-122 CVE-2023-21733: Windows Bind Filter Driver Elevation of Privilege Vulnerability Windows Bind Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-30205P4MEDIUMCVSS 6.6≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-30205 [MEDIUM] CWE-362 CVE-2022-30205: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2025-48800P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48800 [MEDIUM] CWE-693 CVE-2025-48800: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48003P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48003 [MEDIUM] CWE-693 CVE-2025-48003: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48804P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48804 [MEDIUM] CWE-349 CVE-2025-48804: Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorize Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48818P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48818 [MEDIUM] CWE-367 CVE-2025-48818: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase