Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 31 of 182
CVE-2024-43518P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43518 [HIGH] CWE-122 CVE-2024-43518: Windows Telephony Server Remote Code Execution Vulnerability
Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2026-69494P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69494 [HIGH] CWE-122 CVE-2026-69494: Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-69598P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69598 [HIGH] CWE-131 CVE-2026-69598: Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute cod
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-20925P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20925 [MEDIUM] CWE-73 CVE-2026-20925: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-21224P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21224 [HIGH] CWE-416 CVE-2025-21224: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2022-21893P3HIGHCVSS 8.0≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21893 [HIGH] CVE-2022-21893: Remote Desktop Protocol Remote Code Execution Vulnerability
Remote Desktop Protocol Remote Code Execution Vulnerability
nvd
CVE-2025-54916P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54916 [HIGH] CWE-121 CVE-2025-54916: Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2025-59516P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-59516 [HIGH] CWE-73 CVE-2025-59516: Missing authentication for critical function in Windows Storage VSP Driver allows an authorized atta
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62454P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62454 [HIGH] CWE-122 CVE-2025-62454: Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker t
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38049P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.46512024-07-09
CVE-2024-38049 [HIGH] CWE-73 CVE-2024-38049: Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
nvd
CVE-2025-58722P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58722 [HIGH] CWE-122 CVE-2025-58722: Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locall
Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62472P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62472 [HIGH] CWE-416 CVE-2025-62472: Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attac
Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49118P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49118 [HIGH] CWE-416 CVE-2024-49118: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38045P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.48942024-09-10
CVE-2024-38045 [HIGH] CWE-122 CVE-2024-38045: Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2024-49124P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49124 [HIGH] CWE-362 CVE-2024-49124: Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
nvd
CVE-2024-49127P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49127 [HIGH] CWE-416 CVE-2024-49127: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-20856P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20856 [HIGH] CWE-20 CVE-2026-20856: Improper input validation in Windows Server Update Service allows an unauthorized attacker to execut
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-70342P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70342 [HIGH] CWE-416 CVE-2026-70342: Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to e
Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-42900P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-42900 [HIGH] CWE-362 CVE-2026-42900: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-69462P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69462 [HIGH] CWE-122 CVE-2026-69462: Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privi
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
nvd