VulnSea

windows_10_version_21h2 vulnerabilities

CVEs whose affected-version data names the windows_10_version_21h2 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

624 CVEsRSS

CVE-2026-50302Medium· 4.2
2mo ago

Windows Cryptographic Services Security Feature Bypass Vulnerability

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.33%via CVEORG
CVE-2026-50300Medium· 5.5
2mo ago

Windows DWM Core Library Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-50298Medium· 6.8
2mo ago

Windows Spaceport.sys Elevation of Privilege Vulnerability

Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.44%via CVEORG
CVE-2026-50297High· 7.0
2mo ago

Win32k Elevation of Privilege Vulnerability

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.24%via CVEORG
CVE-2026-50296High· 7.0
2mo ago

DirectX Graphics Kernel Elevation of Privilege Vulnerability

Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-50293High· 7.8
2mo ago

Windows Internal Task Bar Elevation of Privilege Vulnerability

Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.33%via CVEORG
CVE-2026-49807Medium· 6.2
2mo ago

Windows DirectX Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.51%via CVEORG
CVE-2026-50419Low· 3.3
2mo ago

Windows Kernel Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.46%via CVEORG
CVE-2026-50412High· 7.8
2mo ago

Windows NTFS Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50407High· 7.8
2mo ago

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50400High· 7.8
2mo ago

Windows App Package Installer Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50386High· 7.8
2mo ago

Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-50380Critical· 9.6
2mo ago

Windows GDI+ Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.82%via CVEORG
CVE-2026-50363High· 7.8
2mo ago

Windows Push Notifications Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50360High· 8.8
2mo ago

Windows SMB Server Elevation of Privilege Vulnerability

Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.78%via CVEORG
CVE-2026-50343High· 7.8PoC
2mo ago

Microsoft Install Service Elevation of Privilege Vulnerability

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1809EPSS 0.30%via CVEORG
CVE-2026-50341Medium· 5.5
2mo ago

Windows NTFS Information Disclosure Vulnerability

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-50337High· 7.8
2mo ago

Windows Notification Elevation of Privilege Vulnerability

Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50331High· 7.8
2mo ago

Windows Application Model Core API Elevation of Privilege Vulnerability

Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50329High· 7.8
2mo ago

Microsoft DWM Core Library Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-50326High· 7.8
2mo ago

Windows Unified Consent System Elevation of Privilege Vulnerability

Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.33%via CVEORG
CVE-2026-50313High· 7.8
2mo ago

Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-50309High· 7.8
2mo ago

Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50307High· 7.0
2mo ago

Windows TCP/IP Elevation of Privilege Vulnerability

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.28%via CVEORG
CVE-2026-50306High· 7.8
2mo ago

Windows TCP/IP Elevation of Privilege Vulnerability

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50434Medium· 5.5
2mo ago

Windows Push Notification Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.48%via CVEORG
CVE-2026-50430Medium· 5.5
2mo ago

Windows Push Notification Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-50425High· 7.8
2mo ago

Windows Internal System User Profile Elevation of Privilege Vulnerability

Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.33%via CVEORG
CVE-2026-50390High· 7.0
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.28%via CVEORG
CVE-2026-50377Medium· 5.5
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.41%via CVEORG
windows_10_version_21h2 vulnerabilities (CVEs) — page 9 · VulnSea