cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 70 of 182
CVE-2026-20918P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20918 [HIGH] CWE-362 CVE-2026-20918: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69907P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69907 [HIGH] CWE-280 CVE-2026-69907: Improper handling of insufficient permissions or privileges in Windows Enterprise App Management all Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69377P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69377 [HIGH] CWE-862 CVE-2026-69377: Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to ele Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-65773P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65773 [HIGH] CWE-284 CVE-2026-65773: Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locall Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50391P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50391 [HIGH] CWE-269 CVE-2026-50391: Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privi Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50335P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50335 [HIGH] CWE-284 CVE-2026-50335: Improper access control in Windows Operating Systems allows an authorized attacker to elevate privil Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50373P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50373 [HIGH] CWE-284 CVE-2026-50373: Improper access control in Microsoft Windows Search Component allows an authorized attacker to eleva Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50351P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50351 [HIGH] CWE-284 CVE-2026-50351: Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50346P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50346 [HIGH] CWE-285 CVE-2026-50346: Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20861P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20861 [HIGH] CWE-362 CVE-2026-20861: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20858P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20858 [HIGH] CWE-362 CVE-2026-20858: Use after free in Windows Management Services allows an authorized attacker to elevate privileges lo Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20867P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20867 [HIGH] CWE-362 CVE-2026-20867: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20866P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20866 [HIGH] CWE-362 CVE-2026-20866: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20874P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20874 [HIGH] CWE-362 CVE-2026-20874: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20873P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20873 [HIGH] CWE-362 CVE-2026-20873: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49732P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49732 [HIGH] CWE-122 CVE-2025-49732: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50406P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50406 [HIGH] CWE-416 CVE-2026-50406: Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54989P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54989 [HIGH] CWE-416 CVE-2026-54989: Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attack Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50359P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50359 [HIGH] CWE-416 CVE-2026-50359: Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges lo Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50390P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50390 [HIGH] CWE-843 CVE-2026-50390: Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase