Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 34 of 182
CVE-2026-69479P3HIGHCVSS 8.4≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69479 [HIGH] CWE-122 CVE-2026-69479: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-54122P3HIGHCVSS 8.4≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54122 [HIGH] CWE-122 CVE-2026-54122: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-29810P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-29810 [HIGH] CWE-284 CVE-2025-29810: Improper access control in Active Directory Domain Services allows an authorized attacker to elevate
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-37957P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-37957 [HIGH] CVE-2022-37957: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2026-25172P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25172 [HIGH] CWE-122 CVE-2026-25172: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authori
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-25173P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25173 [HIGH] CWE-122 CVE-2026-25173: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authori
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-69623P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69623 [HIGH] CWE-122 CVE-2026-69623: Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute c
Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.
nvd
CVE-2026-26111P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-26111 [HIGH] CWE-122 CVE-2026-26111: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authori
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-20922P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20922 [HIGH] CWE-122 CVE-2026-20922: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-69847P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69847 [HIGH] CWE-122 CVE-2026-69847: Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
nvd
CVE-2026-23674P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-23674 [HIGH] CWE-41 CVE-2026-23674: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to b
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-49789P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49789 [HIGH] CWE-121 CVE-2026-49789: Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges loca
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69284P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69284 [HIGH] CWE-122 CVE-2026-69284: Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privilege
Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-71337P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71337 [HIGH] CWE-121 CVE-2026-71337: Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to
Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69290P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69290 [HIGH] CWE-121 CVE-2026-69290: Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to el
Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69391P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69391 [HIGH] CWE-121 CVE-2026-69391: Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker t
Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62692P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62692 [HIGH] CWE-122 CVE-2026-62692: Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to eleva
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70344P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-70344 [HIGH] CWE-121 CVE-2026-70344: Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62768P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62768 [HIGH] CWE-121 CVE-2026-62768: Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-65671P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65671 [HIGH] CWE-122 CVE-2026-65671: Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
nvd