Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 76 of 182
CVE-2026-77503P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-77503 [HIGH] CWE-125 CVE-2026-77503: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-45607P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45607 [HIGH] CWE-125 CVE-2026-45607: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-69295P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69295 [HIGH] CWE-20 CVE-2026-69295: Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69738P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69738 [HIGH] CWE-122 CVE-2026-69738: Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69900P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69900 [HIGH] CWE-822 CVE-2026-69900: Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized atta
Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69707P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69707 [HIGH] CWE-190 CVE-2026-69707: Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-73002P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73002 [HIGH] CWE-190 CVE-2026-73002: Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69687P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69687 [HIGH] CWE-191 CVE-2026-69687: Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an au
Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69844P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69844 [HIGH] CWE-125 CVE-2026-69844: Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69535P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69535 [HIGH] CWE-122 CVE-2026-69535: Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privilege
Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-77489P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-77489 [HIGH] CWE-476 CVE-2026-77489: Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privi
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69532P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69532 [HIGH] CWE-125 CVE-2026-69532: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69608P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69608 [HIGH] CWE-190 CVE-2026-69608: Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker t
Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69822P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69822 [HIGH] CWE-122 CVE-2026-69822: Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges loc
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69312P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69312 [HIGH] CWE-125 CVE-2026-69312: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70581P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70581 [HIGH] CWE-20 CVE-2026-70581: Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69450P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69450 [HIGH] CWE-125 CVE-2026-69450: Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges lo
Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69561P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69561 [HIGH] CWE-125 CVE-2026-69561: Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges loca
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69298P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69298 [HIGH] CWE-190 CVE-2026-69298: Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70574P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70574 [HIGH] CWE-125 CVE-2026-70574: Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to eleva
Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
nvd