Microsoft Windows 11 Version 21H2 vulnerabilities
1,560 known vulnerabilities affecting microsoft/windows_11_version_21h2.
Total CVEs
1,560
CISA KEV
67
actively exploited
Public exploits
47
Exploited in wild
90
Severity breakdown
CRITICAL51HIGH1137MEDIUM368LOW4
Vulnerabilities
Page 49 of 78
CVE-2023-32034P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.21762023-07-11
CVE-2023-32034 [HIGH] CWE-125 CVE-2023-32034: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-32035P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.21762023-07-11
CVE-2023-32035 [HIGH] CWE-125 CVE-2023-32035: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33169P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.21762023-07-11
CVE-2023-33169 [HIGH] CWE-126 CVE-2023-33169: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2022-22040P3HIGHCVSS 7.3≥ 10.0.0, < 10.0.22000.7952022-07-12
CVE-2022-22040 [HIGH] CVE-2022-22040: Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
nvd
CVE-2023-24948P3HIGHCVSS 7.4≥ 10.0.0, < 10.0.22000.19362023-05-09
CVE-2023-24948 [HIGH] CWE-122 CVE-2023-24948: Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-32054P3HIGHCVSS 7.3≥ 10.0.0, < 10.0.22000.21762023-07-11
CVE-2023-32054 [HIGH] CWE-36 CVE-2023-32054: Volume Shadow Copy Elevation of Privilege Vulnerability
Volume Shadow Copy Elevation of Privilege Vulnerability
nvd
CVE-2024-21302P3MEDIUMCVSS 6.7≥ 10.0.22000.0, < 10.0.19044.57372024-08-08
CVE-2024-21302 [MEDIUM] CWE-284 CVE-2024-21302: Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See K
Summary:
As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability.
An elevation of privilege vulnerability exis
nvd
CVE-2023-32043P3MEDIUMCVSS 6.8≥ 10.0.0, < 10.0.22000.21762023-07-11
CVE-2023-32043 [MEDIUM] CWE-327 CVE-2023-32043: Windows Remote Desktop Security Feature Bypass Vulnerability
Windows Remote Desktop Security Feature Bypass Vulnerability
nvd
CVE-2022-37973P3HIGHCVSS 7.7≥ 10.0.0, < 10.0.22000.10982022-10-11
CVE-2022-37973 [HIGH] CVE-2022-37973: Windows Local Session Manager (LSM) Denial of Service Vulnerability
Windows Local Session Manager (LSM) Denial of Service Vulnerability
nvd
CVE-2022-37998P3HIGHCVSS 7.7≥ 10.0.0, < 10.0.22000.10982022-10-11
CVE-2022-37998 [HIGH] CVE-2022-37998: Windows Local Session Manager (LSM) Denial of Service Vulnerability
Windows Local Session Manager (LSM) Denial of Service Vulnerability
nvd
CVE-2022-21889P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.4342022-01-11
CVE-2022-21889 [HIGH] CVE-2022-21889: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21890P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.4342022-01-11
CVE-2022-21890 [HIGH] CVE-2022-21890: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-35833P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.9782022-09-13
CVE-2022-35833 [HIGH] CVE-2022-35833: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-36585P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.25382023-10-10
CVE-2023-36585 [HIGH] CWE-20 CVE-2023-36585: Windows upnphost.dll Denial of Service Vulnerability
Windows upnphost.dll Denial of Service Vulnerability
nvd
CVE-2022-34701P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.8562022-08-09
CVE-2022-34701 [HIGH] CWE-400 CVE-2022-34701: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2022-33645P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.10982022-10-11
CVE-2022-33645 [HIGH] CVE-2022-33645: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2023-24931P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.18172023-04-11
CVE-2023-24931 [HIGH] CWE-125 CVE-2023-24931: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-21757P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.14552023-01-10
CVE-2023-21757 [HIGH] CWE-476 CVE-2023-21757: Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
nvd
CVE-2022-38041P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.10982022-10-11
CVE-2022-38041 [HIGH] CVE-2022-38041: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-28241P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.22000.18172023-04-11
CVE-2023-28241 [HIGH] CVE-2023-28241: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd