cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 139 of 182
CVE-2026-62881P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62881 [MEDIUM] CWE-122 CVE-2026-62881: Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62769P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62769 [MEDIUM] CWE-122 CVE-2026-62769: Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-65798P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65798 [MEDIUM] CWE-197 CVE-2026-65798: Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62883P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62883 [MEDIUM] CWE-122 CVE-2026-62883: Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-65797P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65797 [MEDIUM] CWE-122 CVE-2026-65797: Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32170P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-32170 [MEDIUM] CWE-415 CVE-2026-32170: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21530P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-21530 [MEDIUM] CWE-415 CVE-2026-21530: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48811P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48811 [MEDIUM] CWE-353 CVE-2025-48811: Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48803P4MEDIUMCVSS 6.7≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48803 [MEDIUM] CWE-353 CVE-2025-48803: Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70582P4MEDIUMCVSS 6.4≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70582 [MEDIUM] CWE-362 CVE-2026-70582: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29954P4MEDIUMCVSS 5.9≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29954 [MEDIUM] CWE-400 CVE-2025-29954: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-32072P4MEDIUMCVSS 6.2≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32072 [MEDIUM] CWE-287 CVE-2026-32072: Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoof Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2026-26169P4MEDIUMCVSS 6.1≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26169 [MEDIUM] CWE-126 CVE-2026-26169: Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information loca Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
nvd
CVE-2026-68874P4MEDIUMCVSS 5.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68874 [MEDIUM] CWE-125 CVE-2026-68874: Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-69591P4MEDIUMCVSS 5.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69591 [MEDIUM] CWE-125 CVE-2026-69591: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a netw Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-69572P4MEDIUMCVSS 5.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69572 [MEDIUM] CWE-125 CVE-2026-69572: Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-69393P4MEDIUMCVSS 5.7≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69393 [MEDIUM] CWE-125 CVE-2026-69393: Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information ov Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network.
nvd
CVE-2022-22041P4MEDIUMCVSS 6.8≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-22041 [MEDIUM] CVE-2022-22041: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-24460P4HIGHCVSS 7.0≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-24460 [HIGH] CVE-2022-24460: Tablet Windows User Interface Application Elevation of Privilege Vulnerability Tablet Windows User Interface Application Elevation of Privilege Vulnerability
nvd
CVE-2022-22042P4MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.18262022-07-12
CVE-2022-22042 [MEDIUM] CVE-2022-22042: Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase