Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 38 of 182
CVE-2026-21236P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21236 [HIGH] CWE-122 CVE-2026-21236: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-21539P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.24862023-01-10
CVE-2023-21539 [HIGH] CWE-125 CVE-2023-21539: Windows Authentication Remote Code Execution Vulnerability
Windows Authentication Remote Code Execution Vulnerability
nvd
CVE-2026-58547P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58547 [HIGH] CWE-122 CVE-2026-58547: Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to el
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48814P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48814 [HIGH] CWE-306 CVE-2025-48814: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an u
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-70330P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-70330 [HIGH] CWE-122 CVE-2026-70330: Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locall
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70304P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-70304 [HIGH] CWE-122 CVE-2026-70304: Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locall
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50680P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50680 [HIGH] CWE-122 CVE-2026-50680: Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges lo
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54992P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54992 [HIGH] CWE-122 CVE-2026-54992: Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-69478P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69478 [HIGH] CWE-122 CVE-2026-69478: Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to el
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-72941P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72941 [HIGH] CWE-122 CVE-2026-72941: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-83967P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-83967 [HIGH] CWE-122 CVE-2026-83967: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69456P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69456 [HIGH] CWE-122 CVE-2026-69456: Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate priv
Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69691P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69691 [HIGH] CWE-122 CVE-2026-69691: Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privile
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69476P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69476 [HIGH] CWE-122 CVE-2026-69476: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69432P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69432 [HIGH] CWE-122 CVE-2026-69432: Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privile
Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70583P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70583 [HIGH] CWE-122 CVE-2026-70583: Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privil
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-72967P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72967 [HIGH] CWE-122 CVE-2026-72967: Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to ele
Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-83988P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-83988 [HIGH] CWE-122 CVE-2026-83988: Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-72944P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72944 [HIGH] CWE-122 CVE-2026-72944: Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privilege
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69604P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69604 [HIGH] CWE-122 CVE-2026-69604: Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privile
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
nvd