Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 134 of 182
CVE-2024-20663P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20663 [MEDIUM] CWE-822 CVE-2024-20663: Windows Message Queuing Client (MSMQC) Information Disclosure
Windows Message Queuing Client (MSMQC) Information Disclosure
nvd
CVE-2025-21349P4MEDIUMCVSS 6.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21349 [MEDIUM] CWE-287 CVE-2025-21349: Windows Remote Desktop Configuration Service Tampering Vulnerability
Windows Remote Desktop Configuration Service Tampering Vulnerability
nvd
CVE-2022-23298P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability
Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-30099P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.45292024-06-11
CVE-2024-30099 [HIGH] CWE-367 CVE-2024-30099: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-36403P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19043.36932023-11-14
CVE-2023-36403 [HIGH] CWE-591 CVE-2023-36403: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43535P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43535 [HIGH] CWE-416 CVE-2024-43535: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43570P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43570 [HIGH] CWE-416 CVE-2024-43570: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-58735P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58735 [HIGH] CWE-416 CVE-2025-58735: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58732P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58732 [HIGH] CWE-416 CVE-2025-58732: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-49084P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49084 [HIGH] CWE-362 CVE-2024-49084: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38136P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38136 [HIGH] CWE-416 CVE-2024-38136: Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
nvd
CVE-2024-38137P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38137 [HIGH] CWE-416 CVE-2024-38137: Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
nvd
CVE-2024-43511P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.51312024-10-08
CVE-2024-43511 [HIGH] CWE-367 CVE-2024-43511: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-58730P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58730 [HIGH] CWE-416 CVE-2025-58730: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58738P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58738 [HIGH] CWE-416 CVE-2025-58738: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58736P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58736 [HIGH] CWE-416 CVE-2025-58736: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58734P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58734 [HIGH] CWE-416 CVE-2025-58734: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58733P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58733 [HIGH] CWE-416 CVE-2025-58733: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2022-41097P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.22512022-11-09
CVE-2022-41097 [MEDIUM] CVE-2022-41097: Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
nvd
CVE-2025-49685P4HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49685 [HIGH] CWE-416 CVE-2025-49685: Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privil
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd