Microsoft Windows 10 Version 21H2 vulnerabilities
2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
123
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13
Vulnerabilities
Page 40 of 146
CVE-2026-50429P3HIGHCVSS 8.2≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50429 [HIGH] CWE-125 CVE-2026-50429: Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-23405P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23405 [HIGH] CWE-190 CVE-2023-23405: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24908P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24908 [HIGH] CWE-190 CVE-2023-24908: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24869P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-24869 [HIGH] CWE-190 CVE-2023-24869: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-21712P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.22512023-04-27
CVE-2023-21712 [HIGH] CWE-362 CVE-2023-21712: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-41088P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.22512022-11-09
CVE-2022-41088 [HIGH] CWE-362 CVE-2022-41088: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-24903P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.29652023-05-09
CVE-2023-24903 [HIGH] CWE-415 CVE-2023-24903: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-23404P3HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23404 [HIGH] CWE-416 CVE-2023-23404: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-30145P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30145 [HIGH] CVE-2022-30145: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
nvd
CVE-2025-53149P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53149 [HIGH] CWE-122 CVE-2025-53149: Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacke
Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24067P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-24067 [HIGH] CWE-122 CVE-2025-24067: Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate p
Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24066P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-24066 [HIGH] CWE-122 CVE-2025-24066: Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24063P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-24063 [HIGH] CWE-122 CVE-2025-24063: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26666P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26666 [HIGH] CWE-122 CVE-2025-26666: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2025-26674P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26674 [HIGH] CWE-122 CVE-2025-26674: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2025-60714P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60714 [HIGH] CWE-122 CVE-2025-60714: Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-27490P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-27490 [HIGH] CWE-122 CVE-2025-27490: Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-35632P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.38032023-12-12
CVE-2023-35632 [HIGH] CWE-190 CVE-2023-35632: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2026-35421P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-35421 [HIGH] CWE-122 CVE-2026-35421: Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-38142P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.34482023-09-12
CVE-2023-38142 [HIGH] CWE-190 CVE-2023-38142: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd