Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 35 of 182
CVE-2026-62877P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62877 [HIGH] CWE-121 CVE-2026-62877: Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges lo
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70346P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-70346 [HIGH] CWE-121 CVE-2026-70346: Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50412P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50412 [HIGH] CWE-121 CVE-2026-50412: Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges loca
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50400P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50400 [HIGH] CWE-121 CVE-2026-50400: Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privil
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-57096P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57096 [HIGH] CWE-122 CVE-2026-57096: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50318P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50318 [HIGH] CWE-121 CVE-2026-50318: Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50387P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50387 [HIGH] CWE-121 CVE-2026-50387: Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges local
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33837P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-33837 [HIGH] CWE-122 CVE-2026-33837: Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40398P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40398 [HIGH] CWE-122 CVE-2026-40398: Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privil
Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20849P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20849 [HIGH] CWE-807 CVE-2026-20849: Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacke
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2025-58726P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-58726 [HIGH] CWE-284 CVE-2025-58726: Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges ov
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69793P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69793 [HIGH] CWE-1288 CVE-2026-69793: Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to
Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-69602P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69602 [HIGH] CWE-416 CVE-2026-69602: Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges o
Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69706P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69706 [HIGH] CWE-416 CVE-2026-69706: Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-24502P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-24502 [MEDIUM] CVE-2022-24502: Windows HTML Platforms Security Feature Bypass Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2022-21920P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21920 [HIGH] CVE-2022-21920: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-22019P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-22019 [HIGH] CVE-2022-22019: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-23253P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-23253 [MEDIUM] CVE-2022-23253: Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
nvd
CVE-2022-24528P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24528 [HIGH] CVE-2022-24528: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-21857P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19043.14662022-01-11
CVE-2022-21857 [HIGH] CVE-2022-21857: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd