cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 68 of 182
CVE-2026-69582P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69582 [HIGH] CWE-126 CVE-2026-69582: Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-59127P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-59127 [HIGH] CWE-190 CVE-2026-59127: Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privile Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62876P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62876 [HIGH] CWE-125 CVE-2026-62876: Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62733P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62733 [HIGH] CWE-125 CVE-2026-62733: Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61932P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61932 [HIGH] CWE-122 CVE-2026-61932: Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62701P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62701 [HIGH] CWE-416 CVE-2026-62701: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62880P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62880 [HIGH] CWE-125 CVE-2026-62880: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50367P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50367 [HIGH] CWE-118 CVE-2026-50367: Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an auth Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50421P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50421 [HIGH] CWE-843 CVE-2026-50421: Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50425P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50425 [HIGH] CWE-416 CVE-2026-50425: Use after free in Windows Internal System User Profile allows an authorized attacker to elevate priv Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50402P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50402 [HIGH] CWE-126 CVE-2026-50402: Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54109P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54109 [HIGH] CWE-122 CVE-2026-54109: Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
nvd
CVE-2026-50435P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50435 [HIGH] CWE-126 CVE-2026-50435: Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges local Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50293P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50293 [HIGH] CWE-416 CVE-2026-50293: Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges loca Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50670P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50670 [HIGH] CWE-20 CVE-2026-50670: Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58536P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58536 [HIGH] CWE-416 CVE-2026-58536: Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate pr Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49800P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49800 [HIGH] CWE-122 CVE-2026-49800: Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authori Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50399P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50399 [HIGH] CWE-125 CVE-2026-50399: Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56182P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-56182 [HIGH] CWE-122 CVE-2026-56182: Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges l Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42982P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-42982 [HIGH] CWE-1288 CVE-2026-42982: Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized a Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase