cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 75 of 182
CVE-2026-84001P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-84001 [HIGH] CWE-125 CVE-2026-84001: Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny servic Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-83989P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-83989 [HIGH] CWE-125 CVE-2026-83989: Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-49787P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49787 [HIGH] CWE-770 CVE-2026-49787: Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized atta Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50496P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50496 [HIGH] CWE-125 CVE-2026-50496: Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-54119P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54119 [HIGH] CWE-835 CVE-2026-54119: Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unautho Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-53132P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53132 [HIGH] CWE-362 CVE-2025-53132: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62457P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62457 [HIGH] CWE-125 CVE-2025-62457: Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevat Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62466P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-62466 [HIGH] CWE-476 CVE-2025-62466: Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60720P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-60720 [HIGH] CWE-126 CVE-2025-60720: Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20822P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20822 [HIGH] CWE-416 CVE-2026-20822: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23673P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-23673 [HIGH] CWE-125 CVE-2026-23673: Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26687P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26687 [HIGH] CWE-416 CVE-2025-26687: Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2025-59277P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.64562025-10-14
CVE-2025-59277 [HIGH] CWE-1287 CVE-2025-59277: Improper validation of specified type of input in Windows Authentication Methods allows an authorize Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49675P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49675 [HIGH] CWE-416 CVE-2025-49675: Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69612P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69612 [HIGH] CWE-36 CVE-2026-69612: Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileg Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-64673P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-64673 [HIGH] CWE-284 CVE-2025-64673: Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges lo Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49726P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49726 [HIGH] CWE-416 CVE-2025-49726: Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54092P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54092 [HIGH] CWE-362 CVE-2025-54092: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-65799P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65799 [HIGH] CWE-122 CVE-2026-65799: Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges lo Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25175P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25175 [HIGH] CWE-125 CVE-2026-25175: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase