Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 58 of 182
CVE-2026-61918P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61918 [HIGH] CWE-125 CVE-2026-61918: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50504P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50504 [HIGH] CWE-126 CVE-2026-50504: Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information ov
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50497P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50497 [HIGH] CWE-193 CVE-2026-50497: Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose info
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-35309P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.32082023-07-11
CVE-2023-35309 [HIGH] CWE-591 CVE-2023-35309: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-38142P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.34482023-09-12
CVE-2023-38142 [HIGH] CWE-190 CVE-2023-38142: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-60704P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60704 [HIGH] CWE-325 CVE-2025-60704: Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2023-35382P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-35382 [HIGH] CWE-416 CVE-2023-35382: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26182P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.41702024-03-12
CVE-2024-26182 [HIGH] CWE-416 CVE-2024-26182: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2026-32161P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-32161 [HIGH] CWE-362 CVE-2026-32161: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2023-35386P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-35386 [HIGH] CWE-125 CVE-2023-35386: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-35756P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.18892023-05-31
CVE-2022-35756 [HIGH] CVE-2022-35756: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2024-30025P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.44122024-05-14
CVE-2024-30025 [HIGH] CWE-125 CVE-2024-30025: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-26211P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.44122024-04-09
CVE-2024-26211 [HIGH] CWE-122 CVE-2024-26211: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2023-23388P3HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23388 [HIGH] CWE-681 CVE-2023-23388: Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43630P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.51312024-11-12
CVE-2024-43630 [HIGH] CWE-121 CVE-2024-43630: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38242P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.48942024-09-10
CVE-2024-38242 [HIGH] CWE-122 CVE-2024-38242: Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-30068P3HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.45292024-06-11
CVE-2024-30068 [HIGH] CWE-125 CVE-2024-30068: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-37974P3MEDIUMCVSS 6.5≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-37974 [MEDIUM] CVE-2022-37974: Windows Mixed Reality Developer Tools Information Disclosure Vulnerability
Windows Mixed Reality Developer Tools Information Disclosure Vulnerability
nvd
CVE-2026-62702P3HIGHCVSS 8.6≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62702 [HIGH] CWE-476 CVE-2026-62702: Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
nvd
CVE-2022-30150P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30150 [HIGH] CWE-287 CVE-2022-30150: Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
nvd