Microsoft Windows 10 Version 21H2 vulnerabilities
2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
123
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13
Vulnerabilities
Page 15 of 146
CVE-2025-21285P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21285 [HIGH] CWE-476 CVE-2025-21285: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21371P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2022-23294P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-23294 [HIGH] CVE-2022-23294: Windows Event Tracing Remote Code Execution Vulnerability
Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2026-24294P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-24294 [HIGH] CWE-287 CVE-2026-24294: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50177P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-50177 [HIGH] CWE-362 CVE-2025-50177: Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-24487P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24487 [HIGH] CVE-2022-24487: Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
nvd
CVE-2025-21407P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21407 [HIGH] CWE-122 CVE-2025-21407: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21406P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21406 [HIGH] CWE-416 CVE-2025-21406: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21190P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21190 [HIGH] CWE-122 CVE-2025-21190: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21201P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21201 [HIGH] CWE-415 CVE-2025-21201: Windows Telephony Server Remote Code Execution Vulnerability
Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-21200P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.54872025-02-11
CVE-2025-21200 [HIGH] CWE-122 CVE-2025-21200: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2023-21676P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21676 [HIGH] CVE-2023-21676: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2023-21695P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.26042023-02-14
CVE-2023-21695 [HIGH] CWE-122 CVE-2023-21695: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
nvd
CVE-2025-33066P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-33066 [HIGH] CWE-122 CVE-2025-33066: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-32157P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32157 [HIGH] CWE-416 CVE-2026-32157: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50474P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50474 [HIGH] CWE-416 CVE-2026-50474: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-47653P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-47653 [HIGH] CWE-416 CVE-2026-47653: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-34329P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-34329 [HIGH] CWE-122 CVE-2026-34329: Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2026-42975P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-42975 [HIGH] CWE-122 CVE-2026-42975: Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execu
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2026-50692P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50692 [HIGH] CWE-122 CVE-2026-50692: Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privil
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
nvd