cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 122 of 182
CVE-2026-69549P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69549 [HIGH] CWE-125 CVE-2026-69549: Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to eleva Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20831P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20831 [HIGH] CWE-367 CVE-2026-20831: Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock a Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20869P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20869 [HIGH] CWE-362 CVE-2026-20869: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55678P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55678 [HIGH] CWE-416 CVE-2025-55678: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21240P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21240 [HIGH] CWE-367 CVE-2026-21240: Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49762P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-49762 [HIGH] CWE-362 CVE-2025-49762: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55328P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55328 [HIGH] CWE-362 CVE-2025-55328: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69600P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69600 [HIGH] CWE-416 CVE-2026-69600: Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privil Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-72952P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72952 [HIGH] CWE-125 CVE-2026-72952: Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally. Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.
nvd
CVE-2026-69838P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69838 [HIGH] CWE-416 CVE-2026-69838: Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileg Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69735P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69735 [HIGH] CWE-416 CVE-2026-69735: Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privil Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69645P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69645 [HIGH] CWE-416 CVE-2026-69645: Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locall Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69362P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69362 [HIGH] CWE-416 CVE-2026-69362: Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locall Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69560P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69560 [HIGH] CWE-416 CVE-2026-69560: Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges lo Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-71332P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71332 [HIGH] CWE-416 CVE-2026-71332: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to e Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70562P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70562 [HIGH] CWE-415 CVE-2026-70562: Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally. Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69911P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69911 [HIGH] CWE-416 CVE-2026-69911: Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privil Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69413P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69413 [HIGH] CWE-416 CVE-2026-69413: Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to ele Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58619P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58619 [HIGH] CWE-416 CVE-2026-58619: Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges lo Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34341P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-34341 [HIGH] CWE-415 CVE-2026-34341: Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase