Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 9 of 182
CVE-2024-49122P2HIGHCVSS 8.1≥ 10.0.19043.0, < 10.0.19044.52472024-12-12
CVE-2024-49122 [HIGH] CWE-416 CVE-2024-49122: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2026-69676P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69676 [HIGH] CWE-294 CVE-2026-69676: Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute
Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.
nvd
CVE-2026-44815P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-44815 [CRITICAL] CWE-121 CVE-2026-44815: Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code o
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-53143P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53143 [HIGH] CWE-843 CVE-2025-53143: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2025-53145P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53145 [HIGH] CWE-843 CVE-2025-53145: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2025-53144P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.62162025-08-12
CVE-2025-53144 [HIGH] CWE-843 CVE-2025-53144: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2023-36028P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19043.36932023-11-14
CVE-2023-36028 [CRITICAL] CWE-122 CVE-2023-36028: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
nvd
CVE-2023-28302P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-28302 [HIGH] CWE-20 CVE-2023-28302: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2026-69910P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69910 [CRITICAL] CWE-121 CVE-2026-69910: Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over
Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-72982P2CRITICALCVSS 9.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-72982 [CRITICAL] CWE-121 CVE-2026-72982: Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-29962P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29962 [HIGH] CWE-122 CVE-2025-29962: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-21769P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19044.28462023-04-11
CVE-2023-21769 [HIGH] CWE-125 CVE-2023-21769: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-24943P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.29652023-05-09
CVE-2023-24943 [CRITICAL] CWE-122 CVE-2023-24943: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2022-21990P2HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.15862022-03-09
CVE-2022-21990 [HIGH] CVE-2022-21990: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2026-69762P2HIGHCVSS 8.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69762 [HIGH] CWE-121 CVE-2026-69762: Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges ov
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-38140P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.47802024-08-13
CVE-2024-38140 [CRITICAL] CWE-416 CVE-2024-38140: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2023-23415P2CRITICALCVSS 9.8≥ 10.0.19043.0, < 10.0.19044.27282023-03-14
CVE-2023-23415 [CRITICAL] CWE-122 CVE-2023-23415: Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
nvd
CVE-2024-43532P2HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.50112024-10-08
CVE-2024-43532 [HIGH] CWE-636 CVE-2024-43532: Remote Registry Service Elevation of Privilege Vulnerability
Remote Registry Service Elevation of Privilege Vulnerability
nvd
CVE-2022-38044P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-38044 [HIGH] CVE-2022-38044: Windows CD-ROM File System Driver Remote Code Execution Vulnerability
Windows CD-ROM File System Driver Remote Code Execution Vulnerability
nvd
CVE-2024-20674P2HIGHCVSS 8.8≥ 10.0.19043.0, < 10.0.19044.39302024-01-09
CVE-2024-20674 [HIGH] CWE-305 CVE-2024-20674: Windows Kerberos Security Feature Bypass Vulnerability
Windows Kerberos Security Feature Bypass Vulnerability
nvd