Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 116 of 182
CVE-2026-69613P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69613 [HIGH] CWE-416 CVE-2026-69613: Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges loca
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-72926P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72926 [HIGH] CWE-416 CVE-2026-72926: Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate
Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69388P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69388 [HIGH] CWE-416 CVE-2026-69388: Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69891P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69891 [HIGH] CWE-416 CVE-2026-69891: Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69708P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69708 [HIGH] CWE-416 CVE-2026-69708: Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges l
Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69310P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69310 [HIGH] CWE-416 CVE-2026-69310: Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.
Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69711P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69711 [HIGH] CWE-416 CVE-2026-69711: Use after free in Windows Device Association Service allows an authorized attacker to elevate privil
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69889P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69889 [HIGH] CWE-416 CVE-2026-69889: Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69299P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69299 [HIGH] CWE-416 CVE-2026-69299: Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges loca
Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69470P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69470 [HIGH] CWE-416 CVE-2026-69470: Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62726P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62726 [HIGH] CWE-416 CVE-2026-62726: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62723P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62723 [HIGH] CWE-416 CVE-2026-62723: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70307P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-70307 [HIGH] CWE-416 CVE-2026-70307: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62774P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62774 [HIGH] CWE-416 CVE-2026-62774: Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locall
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61346P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61346 [HIGH] CWE-416 CVE-2026-61346: Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locall
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61348P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61348 [HIGH] CWE-416 CVE-2026-61348: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-59125P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59125 [HIGH] CWE-416 CVE-2026-59125: Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate p
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62725P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62725 [HIGH] CWE-416 CVE-2026-62725: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62724P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62724 [HIGH] CWE-416 CVE-2026-62724: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58637P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58637 [HIGH] CWE-416 CVE-2026-58637: Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
nvd