cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13

Vulnerabilities

Page 61 of 182
CVE-2025-59255P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59255 [HIGH] CWE-122 CVE-2025-59255: Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59242P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59242 [HIGH] CWE-122 CVE-2025-59242: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69289P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69289 [HIGH] CWE-59 CVE-2026-69289: Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62832P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62832 [HIGH] CWE-59 CVE-2026-62832: Improper link resolution before file access ('link following') in Windows User Profile Service allow Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61358P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61358 [HIGH] CWE-59 CVE-2026-61358: Improper link resolution before file access ('link following') in Windows Accessibility Infrastructu Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50469P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50469 [HIGH] CWE-59 CVE-2026-50469: Improper link resolution before file access ('link following') in Windows Projected File System allo Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42989P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42989 [HIGH] CWE-59 CVE-2026-42989: Improper link resolution before file access ('link following') in Winlogon allows an authorized atta Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62474P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62474 [HIGH] CWE-284 CVE-2025-62474: Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53789P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-08-12
CVE-2025-53789 [HIGH] CWE-306 CVE-2025-53789: Missing authentication for critical function in Windows StateRepository API allows an authorized att Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-41088P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-41088 [HIGH] CWE-73 CVE-2026-41088: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50312P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50312 [HIGH] CWE-416 CVE-2026-50312: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-24292P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-24292 [HIGH] CWE-416 CVE-2026-24292: Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to eleva Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69407P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69407 [HIGH] CWE-190 CVE-2026-69407: Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate pri Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69324P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69324 [HIGH] CWE-125 CVE-2026-69324: Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70584P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70584 [HIGH] CWE-843 CVE-2026-70584: Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an au Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56177P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-56177 [HIGH] CWE-416 CVE-2026-56177: Use after free in Windows Server allows an authorized attacker to elevate privileges locally. Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62888P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62888 [HIGH] CWE-416 CVE-2026-62888: Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62698P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62698 [HIGH] CWE-197 CVE-2026-62698: Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50337P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50337 [HIGH] CWE-704 CVE-2026-50337: Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate p Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50486P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50486 [HIGH] CWE-416 CVE-2026-50486: Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase