Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 82 of 182
CVE-2025-59505P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-59505 [HIGH] CWE-415 CVE-2025-59505: Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25165P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25165 [HIGH] CWE-476 CVE-2026-25165: Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate pr
Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50697P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50697 [HIGH] CWE-200 CVE-2026-50697: Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59290P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-10-14
CVE-2025-59290 [HIGH] CWE-416 CVE-2025-59290: Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47982P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-47982 [HIGH] CWE-20 CVE-2025-47982: Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate pri
Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47159P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-47159 [HIGH] CWE-693 CVE-2025-47159: Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an author
Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54111P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54111 [HIGH] CWE-416 CVE-2025-54111: Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate pr
Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49660P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49660 [HIGH] CWE-416 CVE-2025-49660: Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59511P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-59511 [HIGH] CWE-73 CVE-2025-59511: External control of file name or path in Windows WLAN Service allows an authorized attacker to eleva
External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23672P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-23672 [HIGH] CWE-125 CVE-2026-23672: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-50498P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50498 [HIGH] CWE-125 CVE-2026-50498: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-49790P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49790 [HIGH] CWE-122 CVE-2026-49790: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2025-59514P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-59514 [HIGH] CWE-269 CVE-2025-59514: Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevat
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25174P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-25174 [HIGH] CWE-125 CVE-2026-25174: Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate pr
Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50441P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50441 [HIGH] CWE-822 CVE-2026-50441: Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50479P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50479 [HIGH] CWE-822 CVE-2026-50479: Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate pri
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40404P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-40404 [HIGH] CWE-122 CVE-2026-40404: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-40409P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-40409 [HIGH] CWE-197 CVE-2026-40409: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2025-55224P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-55224 [HIGH] CWE-362 CVE-2025-55224: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd
CVE-2025-55228P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-55228 [HIGH] CWE-362 CVE-2025-55228: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd