cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 52 of 182
CVE-2026-69534P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69534 [HIGH] CWE-77 CVE-2026-69534: Improper neutralization of special elements used in a command ('command injection') in Windows Progr Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50451P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50451 [HIGH] CWE-306 CVE-2026-50451: Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) all Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50459P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50459 [HIGH] CWE-416 CVE-2026-50459: Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-50333P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50333 [HIGH] CWE-306 CVE-2026-50333: Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26160P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26160 [HIGH] CWE-306 CVE-2026-26160: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an a Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26159P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26159 [HIGH] CWE-306 CVE-2026-26159: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an a Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-72932P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72932 [HIGH] CWE-126 CVE-2026-72932: Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclos Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-32056P3CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-32056 [CRITICAL] CWE-59 CVE-2023-32056: Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
nvd
CVE-2026-50445P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50445 [HIGH] CWE-126 CVE-2026-50445: Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a netwo Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58535P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58535 [HIGH] CWE-908 CVE-2026-58535: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58533P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58533 [HIGH] CWE-908 CVE-2026-58533: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2024-38241P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.48942024-09-10
CVE-2024-38241 [HIGH] CWE-20 CVE-2024-38241: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38125P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38125 [HIGH] CWE-197 CVE-2024-38125: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2026-69397P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69397 [HIGH] CWE-416 CVE-2026-69397: Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-42993P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42993 [HIGH] CWE-122 CVE-2026-42993: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-42992P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42992 [HIGH] CWE-122 CVE-2026-42992: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-44799P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-44799 [HIGH] CWE-122 CVE-2026-44799: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-33154P3CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-33154 [CRITICAL] CWE-367 CVE-2023-33154: Windows Partition Management Driver Elevation of Privilege Vulnerability Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2026-62759P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-62759 [HIGH] CWE-290 CVE-2026-62759: Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spo Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
nvd
CVE-2024-43623P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.51312024-11-12
CVE-2024-43623 [HIGH] CWE-190 CVE-2024-43623: Windows NT OS Kernel Elevation of Privilege Vulnerability Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase