Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 48 of 182
CVE-2026-50407P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50407 [HIGH] CWE-122 CVE-2026-50407: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54987P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54987 [HIGH] CWE-122 CVE-2026-54987: Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privil
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50494P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50494 [HIGH] CWE-122 CVE-2026-50494: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-50499P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50499 [HIGH] CWE-122 CVE-2026-50499: Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elev
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50417P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50417 [HIGH] CWE-20 CVE-2026-50417: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-45638P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45638 [HIGH] CWE-122 CVE-2026-45638: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40377P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40377 [HIGH] CWE-122 CVE-2026-40377: Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevat
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61365P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61365 [HIGH] CWE-306 CVE-2026-61365: Missing authentication for critical function in Windows Remote Desktop Services allows an authorized
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61356P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61356 [HIGH] CWE-306 CVE-2026-61356: Missing authentication for critical function in Windows Remote Desktop Services allows an authorized
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61364P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61364 [HIGH] CWE-306 CVE-2026-61364: Missing authentication for critical function in Windows Remote Desktop Services allows an authorized
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42976P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-42976 [HIGH] CWE-306 CVE-2026-42976: Missing authentication for critical function in Windows RPC API allows an authorized attacker to ele
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61367P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61367 [HIGH] CWE-306 CVE-2026-61367: Missing authentication for critical function in Windows Remote Desktop Services allows an authorized
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62777P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62777 [HIGH] CWE-306 CVE-2026-62777: Missing authentication for critical function in Windows License Manager allows an authorized attacke
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40406P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40406 [HIGH] CWE-416 CVE-2026-40406: Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a netw
Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-72927P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72927 [HIGH] CWE-122 CVE-2026-72927: Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2021-43883P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43883 [HIGH] CVE-2021-43883: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2021-43893P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43893 [HIGH] CWE-668 CVE-2021-43893: Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-48563P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-48563 [HIGH] CWE-416 CVE-2026-48563: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-44801P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-44801 [HIGH] CWE-416 CVE-2026-44801: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-56648P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56648 [HIGH] CWE-367 CVE-2026-56648: Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorize
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.
nvd