Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 52 of 182
CVE-2026-69534P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69534 [HIGH] CWE-77 CVE-2026-69534: Improper neutralization of special elements used in a command ('command injection') in Windows Progr
Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50451P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50451 [HIGH] CWE-306 CVE-2026-50451: Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) all
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50459P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50459 [HIGH] CWE-416 CVE-2026-50459: Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-50333P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50333 [HIGH] CWE-306 CVE-2026-50333: Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26160P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26160 [HIGH] CWE-306 CVE-2026-26160: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an a
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26159P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26159 [HIGH] CWE-306 CVE-2026-26159: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an a
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-72932P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72932 [HIGH] CWE-126 CVE-2026-72932: Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclos
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-32056P3CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-32056 [CRITICAL] CWE-59 CVE-2023-32056: Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
nvd
CVE-2026-50445P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50445 [HIGH] CWE-126 CVE-2026-50445: Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a netwo
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58535P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58535 [HIGH] CWE-908 CVE-2026-58535: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58533P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58533 [HIGH] CWE-908 CVE-2026-58533: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2024-38241P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.48942024-09-10
CVE-2024-38241 [HIGH] CWE-20 CVE-2024-38241: Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38125P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38125 [HIGH] CWE-197 CVE-2024-38125: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2026-69397P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69397 [HIGH] CWE-416 CVE-2026-69397: Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network
Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-42993P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42993 [HIGH] CWE-122 CVE-2026-42993: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-42992P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42992 [HIGH] CWE-122 CVE-2026-42992: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-44799P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-44799 [HIGH] CWE-122 CVE-2026-44799: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-33154P3CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-33154 [CRITICAL] CWE-367 CVE-2023-33154: Windows Partition Management Driver Elevation of Privilege Vulnerability
Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2026-62759P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-62759 [HIGH] CWE-290 CVE-2026-62759: Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spo
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
nvd
CVE-2024-43623P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.51312024-11-12
CVE-2024-43623 [HIGH] CWE-190 CVE-2024-43623: Windows NT OS Kernel Elevation of Privilege Vulnerability
Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd