Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 74 of 182
CVE-2025-24062P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-24062 [HIGH] CWE-20 CVE-2025-24062: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24074P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-24074 [HIGH] CWE-20 CVE-2025-24074: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24060P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-24060 [HIGH] CWE-20 CVE-2025-24060: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24073P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-24073 [HIGH] CWE-20 CVE-2025-24073: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-37982P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-37982 [HIGH] CWE-822 CVE-2024-37982: Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2025-24046P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.56082025-03-11
CVE-2025-24046 [HIGH] CWE-416 CVE-2025-24046: Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges lo
Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-24293P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-24293 [HIGH] CWE-476 CVE-2026-24293: Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attac
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54912P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54912 [HIGH] CWE-416 CVE-2025-54912: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60707P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60707 [HIGH] CWE-416 CVE-2025-60707: Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevat
Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20832P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20832 [HIGH] CWE-415 CVE-2026-20832: Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerabili
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
nvd
CVE-2025-32712P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.59652025-06-10
CVE-2025-32712 [HIGH] CWE-416 CVE-2025-32712: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62455P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62455 [HIGH] CWE-20 CVE-2025-62455: Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privil
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69328P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69328 [HIGH] CWE-426 CVE-2026-69328: Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56174P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-56174 [HIGH] CWE-426 CVE-2026-56174: Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privilege
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53726P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53726 [HIGH] CWE-843 CVE-2025-53726: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53724P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53724 [HIGH] CWE-843 CVE-2025-53724: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50153P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-50153 [HIGH] CWE-416 CVE-2025-50153: Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locall
Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49761P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-49761 [HIGH] CWE-416 CVE-2025-49761: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53151P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53151 [HIGH] CWE-416 CVE-2025-53151: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69881P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69881 [HIGH] CWE-476 CVE-2026-69881: Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service ov
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.
nvd