Microsoft Windows 10 Version 21H2 vulnerabilities
2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
123
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13
Vulnerabilities
Page 34 of 146
CVE-2023-41770P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-41770 [HIGH] CWE-416 CVE-2023-41770: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2026-42986P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42986 [HIGH] CWE-416 CVE-2026-42986: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-35297P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35297 [HIGH] CWE-843 CVE-2023-35297: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28283P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.29652023-05-09
CVE-2023-28283 [HIGH] CWE-591 CVE-2023-28283: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30139P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30139 [HIGH] CVE-2022-30139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-57087P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57087 [HIGH] CWE-122 CVE-2026-57087: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-64679P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-12-09
CVE-2025-64679 [HIGH] CWE-122 CVE-2025-64679: Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21236P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21236 [HIGH] CWE-122 CVE-2026-21236: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21246P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21246 [HIGH] CWE-122 CVE-2026-21246: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26668P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26668 [HIGH] CWE-122 CVE-2025-26668: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-59242P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59242 [HIGH] CWE-122 CVE-2025-59242: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50407P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50407 [HIGH] CWE-122 CVE-2026-50407: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59191P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59191 [HIGH] CWE-122 CVE-2025-59191: Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attac
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45638P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45638 [HIGH] CWE-122 CVE-2026-45638: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49184P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49184 [HIGH] CWE-122 CVE-2026-49184: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50482P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50482 [HIGH] CWE-122 CVE-2026-50482: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-58640P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58640 [HIGH] CWE-122 CVE-2026-58640: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-49175P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49175 [HIGH] CWE-122 CVE-2026-49175: Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locall
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50309P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50309 [HIGH] CWE-122 CVE-2026-50309: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-54987P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54987 [HIGH] CWE-122 CVE-2026-54987: Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privil
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd