cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 127 of 182
CVE-2023-32034P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-32034 [HIGH] CWE-125 CVE-2023-32034: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-32035P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-32035 [HIGH] CWE-125 CVE-2023-32035: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33169P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-33169 [HIGH] CWE-126 CVE-2023-33169: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-21526P3HIGHCVSS 7.4≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-21526 [HIGH] CVE-2023-21526: Windows Netlogon Information Disclosure Vulnerability Windows Netlogon Information Disclosure Vulnerability
nvd
CVE-2023-24948P3HIGHCVSS 7.4≥ 10.0.19043.0, < 10.0.19044.29652023-05-09
CVE-2023-24948 [HIGH] CWE-122 CVE-2023-24948: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-32054P3HIGHCVSS 7.3≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-32054 [HIGH] CWE-36 CVE-2023-32054: Volume Shadow Copy Elevation of Privilege Vulnerability Volume Shadow Copy Elevation of Privilege Vulnerability
nvd
CVE-2024-21302P3MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.47802024-08-08
CVE-2024-21302 [MEDIUM] CWE-284 CVE-2024-21302: Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See K Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exis
nvd
CVE-2026-69482P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69482 [HIGH] CWE-379 CVE-2026-69482: Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.
nvd
CVE-2025-33057P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-33057 [MEDIUM] CWE-476 CVE-2025-33057: Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.
nvd
CVE-2025-53147P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53147 [HIGH] CWE-416 CVE-2025-53147: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54115P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54115 [HIGH] CWE-362 CVE-2025-54115: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53137P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53137 [HIGH] CWE-416 CVE-2025-53137: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29841P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29841 [HIGH] CWE-362 CVE-2025-29841: Concurrent execution using shared resource with improper synchronization ('race condition') in Unive Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54112P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54112 [HIGH] CWE-416 CVE-2025-54112: Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges l Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53718P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53718 [HIGH] CWE-416 CVE-2025-53718: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50167P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-50167 [HIGH] CWE-362 CVE-2025-50167: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53721P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53721 [HIGH] CWE-416 CVE-2025-53721: Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevat Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60717P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60717 [HIGH] CWE-416 CVE-2025-60717: Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privil Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59515P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-59515 [HIGH] CWE-416 CVE-2025-59515: Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privil Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55223P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-55223 [HIGH] CWE-362 CVE-2025-55223: Concurrent execution using shared resource with improper synchronization ('race condition') in Graph Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase