Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 99 of 182
CVE-2026-21253P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.69372026-02-10
CVE-2026-21253 [HIGH] CWE-416 CVE-2026-21253: Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69492P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69492 [HIGH] CWE-122 CVE-2026-69492: Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to e
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-41108P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-41108 [HIGH] CWE-122 CVE-2026-41108: Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69563P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69563 [HIGH] CWE-122 CVE-2026-69563: Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized a
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20847P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.68092026-01-13
CVE-2026-20847 [MEDIUM] CWE-200 CVE-2026-20847: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-57982P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-57982 [MEDIUM] CWE-908 CVE-2026-57982: Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information o
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50302P3MEDIUMCVSS 6.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50302 [MEDIUM] CWE-295 CVE-2026-50302: Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-37985P4MEDIUMCVSS 5.5≥ 10.0.19043.0, < 10.0.19044.21302022-10-11
CVE-2022-37985 [MEDIUM] CVE-2022-37985: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2023-35383P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-35383 [HIGH] CWE-190 CVE-2023-35383: Microsoft Message Queuing Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2022-21901P3HIGHCVSS 8.0≥ 10.0.19043.0, < 10.0.19044.14662022-01-11
CVE-2022-21901 [HIGH] CVE-2022-21901: Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2022-30166P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19043.17662022-06-15
CVE-2022-30166 [HIGH] CVE-2022-30166: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2023-36567P3HIGHCVSS 7.5≥ 10.0.19043.0, < 10.0.19041.35702023-10-10
CVE-2023-36567 [HIGH] CWE-908 CVE-2023-36567: Windows Deployment Services Information Disclosure Vulnerability
Windows Deployment Services Information Disclosure Vulnerability
nvd
CVE-2023-36906P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36906 [HIGH] CWE-170 CVE-2023-36906: Windows Cryptographic Services Information Disclosure Vulnerability
Windows Cryptographic Services Information Disclosure Vulnerability
nvd
CVE-2022-38004P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-38004 [HIGH] CVE-2022-38004: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-41121P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.23642022-12-13
CVE-2022-41121 [HIGH] CVE-2022-41121: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-34719P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.20062022-09-13
CVE-2022-34719 [HIGH] CVE-2022-34719: Windows Distributed File System (DFS) Elevation of Privilege Vulnerability
Windows Distributed File System (DFS) Elevation of Privilege Vulnerability
nvd
CVE-2023-36907P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.33242023-08-08
CVE-2023-36907 [HIGH] CWE-170 CVE-2023-36907: Windows Cryptographic Services Information Disclosure Vulnerability
Windows Cryptographic Services Information Disclosure Vulnerability
nvd
CVE-2022-24479P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24479 [HIGH] CVE-2022-24479: Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
nvd
CVE-2021-43247P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.19044.14152021-12-15
CVE-2021-43247 [HIGH] CWE-787 CVE-2021-43247: Windows TCP/IP Driver Elevation of Privilege Vulnerability
Windows TCP/IP Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-24550P3HIGHCVSS 7.8≥ 10.0.19043.0, < 10.0.19044.16452022-04-15
CVE-2022-24550 [HIGH] CVE-2022-24550: Windows Telephony Server Elevation of Privilege Vulnerability
Windows Telephony Server Elevation of Privilege Vulnerability
nvd