Msrc Windows 10 Version 21H2 vulnerabilities
2,050 known vulnerabilities affecting msrc/windows_10_version_21h2.
Total CVEs
2,050
CISA KEV
88
actively exploited
Public exploits
34
Exploited in wild
70
Severity breakdown
CRITICAL47HIGH1482MEDIUM512LOW9
Vulnerabilities
Page 29 of 103
CVE-2025-24992MEDIUMCVSS 5.52025-03-11
CVE-2025-24992 [MEDIUM] CWE-126 Windows NTFS Information Disclosure Vulnerability
Windows NTFS Information Disclosure Vulnerability
Description: Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.
FAQ: According to the CVSS metric, the attack vector is local (AV:L) while u
msrc
CVE-2025-21373HIGHCVSS 7.82025-02-11
CVE-2025-21373 [HIGH] CWE-59 Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Installer: Windows Installer
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:N
msrc
CVE-2025-21358HIGHCVSS 7.82025-02-11
CVE-2025-21358 [HIGH] CWE-822 Windows Core Messaging Elevation of Privileges Vulnerability
Windows Core Messaging Elevation of Privileges Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows CoreMessaging: Windows CoreMessaging
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Dis
msrc
CVE-2025-21200HIGHCVSS 8.82025-02-11
CVE-2025-21200 [HIGH] CWE-122 Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An attacker could exploit this vulnerability by tricking a user into sending a request to a malicious server. This could result in the server returning malicious data that might cause arbitrary code execution on the user's system.
FAQ: According to the CVSS metric, the attack vector is ne
msrc
CVE-2025-21367HIGHCVSS 7.82025-02-11
CVE-2025-21367 [HIGH] CWE-416 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Win32 Kernel Subsystem: Windows Win32 Kernel Subsystem
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privile
msrc
CVE-2025-21368HIGHCVSS 8.82025-02-11
CVE-2025-21368 [HIGH] CWE-122 Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To successfully exploit this remote code execution vulnerability, an attacker could send a malicious logon request to the target domain controller.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticat
msrc
CVE-2025-21407HIGHCVSS 8.82025-02-11
CVE-2025-21407 [HIGH] CWE-122 Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution?
This attack requires a client to connect to a malicious server, and that could allow the attacker to gain code execution on the client.
FAQ: How could an attacker exploit
msrc
CVE-2025-21201HIGHCVSS 8.82025-02-11
CVE-2025-21201 [HIGH] CWE-415 Windows Telephony Server Remote Code Execution Vulnerability
Windows Telephony Server Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution?
This attack requires a client to connect to a malicious server, and that could allow the attacker to gain code execution on the client.
FAQ: How could an attacker exploit th
msrc
CVE-2025-21375HIGHCVSS 7.82025-02-11
CVE-2025-21375 [HIGH] CWE-20 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Microsoft Streaming Service: Microsoft Streaming Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Eleva
msrc
CVE-2025-21414HIGHCVSS 7.02025-02-11
CVE-2025-21414 [HIGH] CWE-122 Windows Core Messaging Elevation of Privileges Vulnerability
Windows Core Messaging Elevation of Privileges Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and take additional actions prior to exploitation to prepare the target environment.
FAQ: What privileges could
msrc
CVE-2025-21351HIGHCVSS 7.52025-02-11
CVE-2025-21351 [HIGH] CWE-400 Windows Active Directory Domain Services API Denial of Service Vulnerability
Windows Active Directory Domain Services API Denial of Service Vulnerability
Active Directory Domain Services: Active Directory Domain Services
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.asp
msrc
CVE-2025-21369HIGHCVSS 8.82025-02-11
CVE-2025-21369 [HIGH] CWE-122 Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To successfully exploit this remote code execution vulnerability, an attacker could send a malicious logon request to the target domain controller.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticat
msrc
CVE-2025-21376HIGHCVSS 8.12025-02-11
CVE-2025-21376 [HIGH] CWE-362 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: How could an attacker exploit this vulnerability?
An unauthenticated attacke
msrc
CVE-2025-21184HIGHCVSS 7.02025-02-11
CVE-2025-21184 [HIGH] CWE-122 Windows Core Messaging Elevation of Privileges Vulnerability
Windows Core Messaging Elevation of Privileges Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and take additional actions prior to exploitation to prepare the target environment.
FAQ: What privileges could
msrc
CVE-2025-21371HIGHCVSS 8.82025-02-11
CVE-2025-21371 [HIGH] CWE-122 Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution?
This attack requires a client to connect to a malicious server, and that could allow the attacker to gain code execution on the client.
FAQ: How could an attacker exploit
msrc
CVE-2025-21418HIGHCVSS 7.8KEV2025-02-11
CVE-2025-21418 [HIGH] CWE-122 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Ancillary Function Driver for WinSock: Windows Ancillary Function Driver for WinSock
Microsoft: Microsoft
msrc
CVE-2025-21419HIGHCVSS 7.12025-02-11
CVE-2025-21419 [HIGH] CWE-59 Windows Setup Files Cleanup Elevation of Privilege Vulnerability
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N), but could lead to major loss on integrity (I:H) and availability (A:H). What does that mean for this vulnerability?
This vulnerability does not allow disclosure of any confidential information, but could allow
msrc
CVE-2025-21406HIGHCVSS 8.82025-02-11
CVE-2025-21406 [HIGH] CWE-416 Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An attacker could exploit this vulnerability by tricking a user into sending a request to a malicious server. This could result in the server returning malicious data that might cause arbitrary code execution on the user's system.
FAQ: According to the CVSS metric, the attack vector is ne
msrc
CVE-2025-21391HIGHCVSS 7.1KEV2025-02-11
CVE-2025-21391 [HIGH] CWE-59 Windows Storage Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker would be able to delete targeted files on a system.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N), but could lead to major loss on integrity (I:H) and availability (A:H).
msrc
CVE-2025-21420HIGHCVSS 7.82025-02-11
CVE-2025-21420 [HIGH] CWE-59 Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Disk Cleanup Tool: Windows Disk Cleanup Tool
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: P
msrc