cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 76 of 182
CVE-2026-77503P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-77503 [HIGH] CWE-125 CVE-2026-77503: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-45607P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45607 [HIGH] CWE-125 CVE-2026-45607: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-69295P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69295 [HIGH] CWE-20 CVE-2026-69295: Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69738P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69738 [HIGH] CWE-122 CVE-2026-69738: Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69900P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69900 [HIGH] CWE-822 CVE-2026-69900: Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized atta Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69707P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69707 [HIGH] CWE-190 CVE-2026-69707: Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-73002P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73002 [HIGH] CWE-190 CVE-2026-73002: Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69687P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69687 [HIGH] CWE-191 CVE-2026-69687: Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an au Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69844P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69844 [HIGH] CWE-125 CVE-2026-69844: Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69535P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69535 [HIGH] CWE-122 CVE-2026-69535: Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privilege Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-77489P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-77489 [HIGH] CWE-476 CVE-2026-77489: Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privi Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69532P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69532 [HIGH] CWE-125 CVE-2026-69532: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69608P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69608 [HIGH] CWE-190 CVE-2026-69608: Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker t Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69822P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69822 [HIGH] CWE-122 CVE-2026-69822: Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges loc Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69312P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69312 [HIGH] CWE-125 CVE-2026-69312: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70581P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70581 [HIGH] CWE-20 CVE-2026-70581: Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69450P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69450 [HIGH] CWE-125 CVE-2026-69450: Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges lo Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69561P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69561 [HIGH] CWE-125 CVE-2026-69561: Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges loca Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69298P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69298 [HIGH] CWE-190 CVE-2026-69298: Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70574P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70574 [HIGH] CWE-125 CVE-2026-70574: Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to eleva Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase