Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 24 of 182
CVE-2023-23406P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23406 [HIGH] CWE-122 CVE-2023-23406: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2023-24913P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24913 [HIGH] CWE-122 CVE-2023-24913: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2023-21684P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.26042023-02-14
CVE-2023-21684 [HIGH] CWE-191 CVE-2023-21684: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2025-21286P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21286 [HIGH] CWE-122 CVE-2025-21286: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21266P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21266 [HIGH] CWE-122 CVE-2025-21266: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21273P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21273 [HIGH] CWE-122 CVE-2025-21273: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21282P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21282 [HIGH] CWE-122 CVE-2025-21282: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-27481P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-27481 [HIGH] CWE-121 CVE-2025-27481: Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45602P3CRITICALCVSS 9.1≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45602 [CRITICAL] CWE-349 CVE-2026-45602: No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering ov
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
nvd
CVE-2022-30163P3HIGHCVSS 8.5≥ 10.0.19043.0, < 10.0.19044.17662022-06-15
CVE-2022-30163 [HIGH] CWE-362 CVE-2022-30163: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2025-29840P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29840 [HIGH] CWE-121 CVE-2025-29840: Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a
Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69619P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69619 [HIGH] CWE-125 CVE-2026-69619: Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges
Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-83996P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-83996 [HIGH] CWE-122 CVE-2026-83996: Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privi
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21294P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21294 [HIGH] CWE-591 CVE-2025-21294: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2026-69524P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69524 [HIGH] CWE-416 CVE-2026-69524: Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code o
Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69546P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69546 [HIGH] CWE-416 CVE-2026-69546: Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code o
Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-83997P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-83997 [HIGH] CWE-416 CVE-2026-83997: Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69732P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69732 [HIGH] CWE-122 CVE-2026-69732: Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized
Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69325P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69325 [HIGH] CWE-122 CVE-2026-69325: Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over
Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-62781P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62781 [HIGH] CWE-122 CVE-2026-62781: Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a net
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
nvd