cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 57 of 182
CVE-2026-56643P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56643 [HIGH] CWE-416 CVE-2026-56643: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56644P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56644 [HIGH] CWE-416 CVE-2026-56644: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-48583P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-48583 [HIGH] CWE-416 CVE-2026-48583: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34333P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-34333 [HIGH] CWE-190 CVE-2026-34333: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34343P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-34343 [HIGH] CWE-122 CVE-2026-34343: Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized at Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40399P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40399 [HIGH] CWE-121 CVE-2026-40399: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35417P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-35417 [HIGH] CWE-843 CVE-2026-35417: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26132P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-26132 [HIGH] CWE-416 CVE-2026-26132: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58635P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58635 [HIGH] CWE-77 CVE-2026-58635: Improper neutralization of special elements used in a command ('command injection') in Windows Narra Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59191P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59191 [HIGH] CWE-122 CVE-2025-59191: Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attac Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49170P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49170 [HIGH] CWE-285 CVE-2026-49170: Insufficient granularity of access control in Windows StateRepository API allows an authorized attac Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50688P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50688 [HIGH] CWE-416 CVE-2026-50688: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50490P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50490 [HIGH] CWE-416 CVE-2026-50490: Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54129P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54129 [HIGH] CWE-416 CVE-2026-54129: Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50307P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50307 [HIGH] CWE-416 CVE-2026-50307: Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-71330P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71330 [HIGH] CWE-497 CVE-2026-71330: Exposure of sensitive system information to an unauthorized control sphere in Windows Services for N Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-70587P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70587 [HIGH] CWE-170 CVE-2026-70587: Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disc Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-69864P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69864 [HIGH] CWE-416 CVE-2026-69864: Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-35644P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19041.38032023-12-12
CVE-2023-35644 [HIGH] CWE-190 CVE-2023-35644: Windows Sysmain Service Elevation of Privilege Vulnerability Windows Sysmain Service Elevation of Privilege Vulnerability
nvd
CVE-2026-61924P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61924 [HIGH] CWE-125 CVE-2026-61924: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase