Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 28 of 182
CVE-2026-69773P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69773 [HIGH] CWE-122 CVE-2026-69773: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69346P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69346 [HIGH] CWE-122 CVE-2026-69346: Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elev
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69643P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69643 [HIGH] CWE-122 CVE-2026-69643: Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privile
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69727P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69727 [HIGH] CWE-122 CVE-2026-69727: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69826P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69826 [HIGH] CWE-122 CVE-2026-69826: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69371P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69371 [HIGH] CWE-122 CVE-2026-69371: Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privil
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69423P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69423 [HIGH] CWE-122 CVE-2026-69423: Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate priv
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2025-21204P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-21204 [HIGH] CWE-59 CVE-2025-21204: Improper link resolution before file access ('link following') in Windows Update Stack allows an aut
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20921P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20921 [HIGH] CWE-362 CVE-2026-20921: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-38186P3CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-38186 [CRITICAL] CWE-306 CVE-2023-38186: Windows Mobile Device Management Elevation of Privilege Vulnerability
Windows Mobile Device Management Elevation of Privilege Vulnerability
nvd
CVE-2026-20926P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20926 [HIGH] CWE-362 CVE-2026-20926: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20919P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20919 [HIGH] CWE-362 CVE-2026-20919: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20848P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20848 [HIGH] CWE-362 CVE-2026-20848: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20934P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20934 [HIGH] CWE-362 CVE-2026-20934: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69539P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69539 [HIGH] CWE-416 CVE-2026-69539: Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
nvd
CVE-2026-69852P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69852 [HIGH] CWE-122 CVE-2026-69852: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
nvd
CVE-2026-58608P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58608 [HIGH] CWE-362 CVE-2026-58608: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
nvd
CVE-2022-38034P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-38034 [HIGH] CVE-2022-38034: Windows Workstation Service Elevation of Privilege Vulnerability
Windows Workstation Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21851P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21851 [HIGH] CVE-2022-21851: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-21850P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21850 [HIGH] CVE-2022-21850: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd