cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 56 of 182
CVE-2026-49791P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49791 [HIGH] CWE-59 CVE-2026-49791: Improper link resolution before file access ('link following') in Windows Routing and Remote Access Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-64680P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-12-09
CVE-2025-64680 [HIGH] CWE-122 CVE-2025-64680: Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49167P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49167 [HIGH] CWE-416 CVE-2026-49167: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45641P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45641 [HIGH] CWE-843 CVE-2026-45641: Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthori Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-71345P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71345 [HIGH] CWE-787 CVE-2026-71345: Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally. Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.
nvd
CVE-2026-62697P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-62697 [HIGH] CWE-416 CVE-2026-62697: Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges loc Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56172P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-56172 [HIGH] CWE-416 CVE-2026-56172: Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges lo Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69270P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69270 [HIGH] CWE-20 CVE-2026-69270: Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized att Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69307P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69307 [HIGH] CWE-122 CVE-2026-69307: Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized att Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69576P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69576 [HIGH] CWE-416 CVE-2026-69576: Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally. Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69571P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69571 [HIGH] CWE-122 CVE-2026-69571: Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized att Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-65775P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65775 [HIGH] CWE-416 CVE-2026-65775: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62707P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62707 [HIGH] CWE-416 CVE-2026-62707: Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate pr Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62711P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62711 [HIGH] CWE-416 CVE-2026-62711: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54114P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54114 [HIGH] CWE-416 CVE-2026-54114: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50478P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50478 [HIGH] CWE-416 CVE-2026-50478: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50326P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50326 [HIGH] CWE-416 CVE-2026-50326: Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50329P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50329 [HIGH] CWE-416 CVE-2026-50329: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58632P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58632 [HIGH] CWE-416 CVE-2026-58632: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50306P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50306 [HIGH] CWE-190 CVE-2026-50306: Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase