cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 48 of 182
CVE-2026-50407P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50407 [HIGH] CWE-122 CVE-2026-50407: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54987P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54987 [HIGH] CWE-122 CVE-2026-54987: Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privil Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50494P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50494 [HIGH] CWE-122 CVE-2026-50494: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-50499P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50499 [HIGH] CWE-122 CVE-2026-50499: Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elev Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50417P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50417 [HIGH] CWE-20 CVE-2026-50417: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-45638P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45638 [HIGH] CWE-122 CVE-2026-45638: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40377P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40377 [HIGH] CWE-122 CVE-2026-40377: Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevat Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61365P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61365 [HIGH] CWE-306 CVE-2026-61365: Missing authentication for critical function in Windows Remote Desktop Services allows an authorized Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61356P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61356 [HIGH] CWE-306 CVE-2026-61356: Missing authentication for critical function in Windows Remote Desktop Services allows an authorized Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61364P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61364 [HIGH] CWE-306 CVE-2026-61364: Missing authentication for critical function in Windows Remote Desktop Services allows an authorized Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42976P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-42976 [HIGH] CWE-306 CVE-2026-42976: Missing authentication for critical function in Windows RPC API allows an authorized attacker to ele Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61367P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61367 [HIGH] CWE-306 CVE-2026-61367: Missing authentication for critical function in Windows Remote Desktop Services allows an authorized Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62777P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62777 [HIGH] CWE-306 CVE-2026-62777: Missing authentication for critical function in Windows License Manager allows an authorized attacke Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40406P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40406 [HIGH] CWE-416 CVE-2026-40406: Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a netw Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-72927P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72927 [HIGH] CWE-122 CVE-2026-72927: Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally. Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2021-43883P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43883 [HIGH] CVE-2021-43883: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2021-43893P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43893 [HIGH] CWE-668 CVE-2021-43893: Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-48563P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-48563 [HIGH] CWE-416 CVE-2026-48563: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-44801P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-44801 [HIGH] CWE-416 CVE-2026-44801: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-56648P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56648 [HIGH] CWE-367 CVE-2026-56648: Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorize Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase