Microsoft Windows 10 Version 21H2 vulnerabilities

2,449 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
2,449
CISA KEV
94
actively exploited
Public exploits
36
Exploited in wild
75
Severity breakdown
CRITICAL60HIGH1758MEDIUM621LOW10

Vulnerabilities

Page 39 of 123
CVE-2025-21378HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21378 [HIGH] CWE-122 CVE-2025-21378: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2025-21300HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21300 [HIGH] CWE-400 CVE-2025-21300: Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
nvd
CVE-2025-21409HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21409 [HIGH] CWE-122 CVE-2025-21409: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21234HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21234 [HIGH] CWE-20 CVE-2025-21234: Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
nvd
CVE-2025-21339HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21339 [HIGH] CWE-122 CVE-2025-21339: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21417HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21417 [HIGH] CWE-122 CVE-2025-21417: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21281HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21281 [HIGH] CWE-416 CVE-2025-21281: Microsoft COM for Windows Elevation of Privilege Vulnerability Microsoft COM for Windows Elevation of Privilege Vulnerability
nvd
CVE-2025-21286HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21286 [HIGH] CWE-122 CVE-2025-21286: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21303HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21303 [HIGH] CWE-122 CVE-2025-21303: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21244HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21244 [HIGH] CWE-190 CVE-2025-21244: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21287HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21287 [HIGH] CWE-269 CVE-2025-21287: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2025-21271HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21271 [HIGH] CWE-126 CVE-2025-21271: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-21304HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21304 [HIGH] CWE-416 CVE-2025-21304: Microsoft DWM Core Library Elevation of Privilege Vulnerability Microsoft DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2025-21224HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21224 [HIGH] CWE-416 CVE-2025-21224: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2025-21334HIGHCVSS 7.8KEV≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21334 [HIGH] CWE-416 CVE-2025-21334: Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
nvd
CVE-2025-21289HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21289 [HIGH] CWE-400 CVE-2025-21289: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21389HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21389 [HIGH] CWE-400 CVE-2025-21389: Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an un Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21295HIGHCVSS 8.1≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21295 [HIGH] CWE-416 CVE-2025-21295: SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
nvd
CVE-2025-21338HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21338 [HIGH] CWE-190 GDI+ Remote Code Execution Vulnerability GDI+ Remote Code Execution Vulnerability GDI+ Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21302HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.53712025-01-14
CVE-2025-21302 [HIGH] CWE-122 CVE-2025-21302: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd