Microsoft Windows 10 Version 21H2 vulnerabilities
2,906 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
2,906
CISA KEV
95
actively exploited
Public exploits
67
Exploited in wild
123
Severity breakdown
CRITICAL79HIGH2093MEDIUM721LOW13
Vulnerabilities
Page 62 of 146
CVE-2025-49721P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49721 [HIGH] CWE-122 CVE-2025-49721: Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate pri
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-53800P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-53800 [HIGH] CWE-1419 CVE-2025-53800: No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privi
No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-57095P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57095 [HIGH] CWE-200 CVE-2026-57095: Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-26648P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26648 [HIGH] CWE-416 CVE-2025-26648: Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker t
Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54124P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54124 [HIGH] CWE-122 CVE-2026-54124: Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code l
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-54091P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54091 [HIGH] CWE-122 CVE-2025-54091: Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privilege
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59207P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59207 [HIGH] CWE-20 CVE-2025-59207: Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25165P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25165 [HIGH] CWE-476 CVE-2026-25165: Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate pr
Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47976P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-47976 [HIGH] CWE-416 CVE-2025-47976: Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55701P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-55701 [HIGH] CWE-1287 CVE-2025-55701: Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47982P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-47982 [HIGH] CWE-20 CVE-2025-47982: Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate pri
Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49660P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49660 [HIGH] CWE-416 CVE-2025-49660: Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23672P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-23672 [HIGH] CWE-125 CVE-2026-23672: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-25174P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25174 [HIGH] CWE-125 CVE-2026-25174: Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate pr
Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50479P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50479 [HIGH] CWE-822 CVE-2026-50479: Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate pri
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47991P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-47991 [HIGH] CWE-416 CVE-2025-47991: Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privi
Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48000P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-48000 [HIGH] CWE-362 CVE-2025-48000: Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevat
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50697P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50697 [HIGH] CWE-200 CVE-2026-50697: Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-26248P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.42912024-04-09
CVE-2024-26248 [HIGH] CWE-303 CVE-2024-26248: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2025-54895P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54895 [HIGH] CWE-190 CVE-2025-54895: Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker
Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
nvd