Microsoft Windows 11 21H2 vulnerabilities

799 known vulnerabilities affecting microsoft/windows_11_21h2.

Total CVEs
799
CISA KEV
56
actively exploited
Public exploits
18
Exploited in wild
55
Severity breakdown
CRITICAL34HIGH572MEDIUM192LOW1

Vulnerabilities

Page 15 of 40
CVE-2024-26176HIGHCVSS 7.8fixed in 10.0.22000.28362024-03-12
CVE-2024-26176 [HIGH] CWE-126 CVE-2024-26176: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-21444HIGHCVSS 8.8fixed in 10.0.22000.28992024-03-12
CVE-2024-21444 [HIGH] CWE-190 CVE-2024-21444: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21443HIGHCVSS 7.3fixed in 10.0.22000.28362024-03-12
CVE-2024-21443 [HIGH] CWE-416 CVE-2024-21443: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-21445HIGHCVSS 7.0fixed in 10.0.22000.28362024-03-12
CVE-2024-21445 [HIGH] CWE-415 CVE-2024-21445: Windows USB Print Driver Elevation of Privilege Vulnerability Windows USB Print Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-21450HIGHCVSS 8.8fixed in 10.0.22000.28992024-03-12
CVE-2024-21450 [HIGH] CWE-190 CVE-2024-21450: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21441HIGHCVSS 8.8fixed in 10.0.22000.28992024-03-12
CVE-2024-21441 [HIGH] CWE-190 CVE-2024-21441: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21407HIGHCVSS 8.1fixed in 10.0.22000.28362024-03-12
CVE-2024-21407 [HIGH] CWE-416 CVE-2024-21407: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2024-26170HIGHCVSS 7.8fixed in 10.0.22000.28362024-03-12
CVE-2024-26170 [HIGH] CWE-20 CVE-2024-26170: Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
nvd
CVE-2024-26161HIGHCVSS 8.8fixed in 10.0.22000.28992024-03-12
CVE-2024-26161 [HIGH] CWE-122 CVE-2024-26161: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21440HIGHCVSS 8.8fixed in 10.0.22000.28992024-03-12
CVE-2024-21440 [HIGH] CWE-197 CVE-2024-21440: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21429MEDIUMCVSS 6.8fixed in 10.0.22000.28362024-03-12
CVE-2024-21429 [MEDIUM] CWE-197 CVE-2024-21429: Windows USB Hub Driver Remote Code Execution Vulnerability Windows USB Hub Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21430MEDIUMCVSS 6.4fixed in 10.0.22000.28362024-03-12
CVE-2024-21430 [MEDIUM] CWE-125 CVE-2024-21430: Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability
nvd
CVE-2024-26174MEDIUMCVSS 5.5fixed in 10.0.22000.28362024-03-12
CVE-2024-26174 [MEDIUM] CWE-125 CVE-2024-26174: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2024-21431MEDIUMCVSS 6.7fixed in 10.0.22000.28362024-03-12
CVE-2024-21431 [MEDIUM] CWE-732 CVE-2024-21431: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
nvd
CVE-2024-21347HIGHCVSS 7.5fixed in 10.0.22000.27772024-02-13
CVE-2024-21347 [HIGH] CWE-122 CVE-2024-21347: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21370HIGHCVSS 8.8fixed in 10.0.22000.27772024-02-13
CVE-2024-21370 [HIGH] CWE-122 CVE-2024-21370: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21350HIGHCVSS 8.8fixed in 10.0.22000.27772024-02-13
CVE-2024-21350 [HIGH] CWE-190 CVE-2024-21350: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21366HIGHCVSS 8.8fixed in 10.0.22000.27772024-02-13
CVE-2024-21366 [HIGH] CWE-122 CVE-2024-21366: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21405HIGHCVSS 7.0fixed in 10.0.22000.27772024-02-13
CVE-2024-21405 [HIGH] CWE-591 CVE-2024-21405: Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
nvd
CVE-2024-21343HIGHCVSS 7.5fixed in 10.0.22000.27772024-02-13
CVE-2024-21343 [HIGH] CWE-125 CVE-2024-21343: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd