Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 123 of 182
CVE-2026-35416P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-35416 [HIGH] CWE-416 CVE-2026-35416: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42825P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-42825 [HIGH] CWE-416 CVE-2026-42825: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55335P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55335 [HIGH] CWE-362 CVE-2025-55335: Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-62217P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-62217 [HIGH] CWE-362 CVE-2025-62217: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50172P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-50172 [MEDIUM] CWE-770 CVE-2025-50172: Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacke
Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.
nvd
CVE-2026-69430P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69430 [HIGH] CWE-416 CVE-2026-69430: Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges
Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59507P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-59507 [HIGH] CWE-362 CVE-2025-59507: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59508P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-59508 [HIGH] CWE-362 CVE-2025-59508: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59506P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-59506 [HIGH] CWE-362 CVE-2025-59506: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32091P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32091 [HIGH] CWE-362 CVE-2026-32091: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-50321P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50321 [HIGH] CWE-362 CVE-2026-50321: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35418P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-35418 [HIGH] CWE-367 CVE-2026-35418: Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate pr
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34337P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-34337 [HIGH] CWE-362 CVE-2026-34337: Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate pr
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-68824P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68824 [HIGH] CWE-362 CVE-2026-68824: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69466P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69466 [HIGH] CWE-367 CVE-2026-69466: Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to
Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69319P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69319 [HIGH] CWE-362 CVE-2026-69319: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62734P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62734 [HIGH] CWE-362 CVE-2026-62734: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62748P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62748 [HIGH] CWE-362 CVE-2026-62748: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-59122P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59122 [HIGH] CWE-362 CVE-2026-59122: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-59126P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59126 [HIGH] CWE-362 CVE-2026-59126: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
nvd