Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 37 of 182
CVE-2025-49740P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49740 [HIGH] CWE-693 CVE-2025-49740: Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a secu
Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-24291P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-24291 [HIGH] CWE-732 CVE-2026-24291: Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBro
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21255P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21255 [HIGH] CWE-284 CVE-2026-21255: Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security featur
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-49795P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49795 [HIGH] CWE-416 CVE-2026-49795: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50382P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50382 [HIGH] CWE-822 CVE-2026-50382: Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code local
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
nvd
CVE-2023-21543P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21543 [HIGH] CWE-400 CVE-2023-21543: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2024-30089P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.45292024-06-11
CVE-2024-30089 [HIGH] CWE-416 CVE-2024-30089: Microsoft Streaming Service Elevation of Privilege Vulnerability
Microsoft Streaming Service Elevation of Privilege Vulnerability
nvd
CVE-2024-30020P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30020 [HIGH] CWE-122 CVE-2024-30020: Windows Cryptographic Services Remote Code Execution Vulnerability
Windows Cryptographic Services Remote Code Execution Vulnerability
nvd
CVE-2024-49126P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49126 [HIGH] CWE-416 CVE-2024-49126: Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
nvd
CVE-2025-27487P3HIGHCVSS 8.0≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-27487 [HIGH] CWE-122 CVE-2025-27487: Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code ov
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
nvd
CVE-2026-56189P3HIGHCVSS 8.4≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56189 [HIGH] CWE-122 CVE-2026-56189: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-49123P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.52472024-12-12
CVE-2024-49123 [HIGH] CWE-591 CVE-2024-49123: Windows Remote Desktop Services Remote Code Execution Vulnerability
Windows Remote Desktop Services Remote Code Execution Vulnerability
nvd
CVE-2024-49132P3HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.52472024-12-12
CVE-2024-49132 [HIGH] CWE-416 CVE-2024-49132: Windows Remote Desktop Services Remote Code Execution Vulnerability
Windows Remote Desktop Services Remote Code Execution Vulnerability
nvd
CVE-2023-23416P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23416 [HIGH] CWE-20 CVE-2023-23416: Windows Cryptographic Services Remote Code Execution Vulnerability
Windows Cryptographic Services Remote Code Execution Vulnerability
nvd
CVE-2022-22715P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.15262022-02-09
CVE-2022-22715 [HIGH] CWE-191 CVE-2022-22715: Named Pipe File System Elevation of Privilege Vulnerability
Named Pipe File System Elevation of Privilege Vulnerability
nvd
CVE-2023-36400P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19043.36932023-11-14
CVE-2023-36400 [HIGH] CWE-122 CVE-2023-36400: Windows HMAC Key Derivation Elevation of Privilege Vulnerability
Windows HMAC Key Derivation Elevation of Privilege Vulnerability
nvd
CVE-2025-62458P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62458 [HIGH] CWE-122 CVE-2025-62458: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privile
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-36903P3CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36903 [CRITICAL] CWE-59 CVE-2023-36903: Windows System Assessment Tool Elevation of Privilege Vulnerability
Windows System Assessment Tool Elevation of Privilege Vulnerability
nvd
CVE-2026-20864P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20864 [HIGH] CWE-122 CVE-2026-20864: Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attac
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21239P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21239 [HIGH] CWE-122 CVE-2026-21239: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd