cbcvebase.

Microsoft Windows 10 Version 21H2 vulnerabilities

3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.

Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13

Vulnerabilities

Page 93 of 182
CVE-2025-62213P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.65752025-11-11
CVE-2025-62213 [HIGH] CWE-416 CVE-2025-62213: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69710P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69710 [HIGH] CWE-362 CVE-2026-69710: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54103P3HIGHCVSS 7.4≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54103 [HIGH] CWE-416 CVE-2025-54103: Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-54911P3HIGHCVSS 7.3≥ 10.0.19044.0, < 10.0.19044.63322025-09-09
CVE-2025-54911 [HIGH] CWE-416 CVE-2025-54911: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49690P3HIGHCVSS 7.4≥ 10.0.19044.0, < 10.0.19044.60932025-07-08
CVE-2025-49690 [HIGH] CWE-362 CVE-2025-49690: Concurrent execution using shared resource with improper synchronization ('race condition') in Capab Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-69451P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69451 [HIGH] CWE-416 CVE-2026-69451: Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privil Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-68835P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68835 [HIGH] CWE-416 CVE-2026-68835: Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileg Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-69358P3HIGHCVSS 7.1≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69358 [HIGH] CWE-908 CVE-2026-69358: Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
nvd
CVE-2026-68884P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68884 [HIGH] CWE-122 CVE-2026-68884: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-68897P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-68897 [HIGH] CWE-122 CVE-2026-68897: Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privil Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70568P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70568 [HIGH] CWE-122 CVE-2026-70568: Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to ele Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69621P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69621 [HIGH] CWE-122 CVE-2026-69621: Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privilege Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69394P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69394 [HIGH] CWE-122 CVE-2026-69394: Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privile Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62753P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62753 [HIGH] CWE-122 CVE-2026-62753: Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges l Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45653P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45653 [HIGH] CWE-122 CVE-2026-45653: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26635P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.57372025-04-08
CVE-2025-26635 [MEDIUM] CWE-1390 CVE-2025-26635: Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
nvd
CVE-2026-20812P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20812 [MEDIUM] CWE-20 CVE-2026-20812: Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authoriz Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.
nvd
CVE-2022-29105P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.17062022-05-10
CVE-2022-29105 [HIGH] CVE-2022-29105: Microsoft Windows Media Foundation Remote Code Execution Vulnerability Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2021-43232P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43232 [HIGH] CVE-2021-43232: Windows Event Tracing Remote Code Execution Vulnerability Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2022-26918P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.16452022-04-15
CVE-2022-26918 [HIGH] CVE-2022-26918: Windows Fax Compose Form Remote Code Execution Vulnerability Windows Fax Compose Form Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 Version 21H2 vulnerabilities | cvebase