📦 Windows 10 21h1

by Microsoft

🔍 What is Windows 10 21h1?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-30080

CRITICAL CVSS 9.8 Jun 11, 2024

CVE-2024-30080 is a critical remote code execution vulnerability in Microsoft Message Queuing (MSMQ) that allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges by sending s...

CVE-2022-35744

CRITICAL CVSS 9.8 May 31, 2023

CVE-2022-35744 is a critical remote code execution vulnerability in Windows Point-to-Point Protocol (PPP) that allows unauthenticated attackers to execute arbitrary code on affected systems. This affe...

CVE-2024-38257

HIGH CVSS 7.5 Sep 10, 2024

This vulnerability in Microsoft's AllJoyn API allows attackers to read sensitive information from memory without proper authorization. It affects systems running vulnerable versions of Windows that ha...

CVE-2024-38250

HIGH CVSS 7.8 Sep 10, 2024

This Windows Graphics Component vulnerability allows an attacker to gain SYSTEM-level privileges on affected systems by exploiting a buffer overflow condition. It affects Windows operating systems wit...

CVE-2024-38046

HIGH CVSS 7.8 Sep 10, 2024

This PowerShell vulnerability allows authenticated attackers to execute arbitrary code with elevated privileges on affected systems. It affects Windows systems with PowerShell installed, primarily imp...

CVE-2024-21357

HIGH CVSS 8.1 Feb 13, 2024

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General Multicast) packets. It affects Windows systems with...

CVE-2023-36585

HIGH CVSS 7.5 Oct 10, 2023

This vulnerability in Windows upnphost.dll allows attackers to cause a denial of service (DoS) by sending specially crafted requests to the Universal Plug and Play (UPnP) service. It affects Windows s...

CVE-2023-36594

HIGH CVSS 7.8 Oct 10, 2023

This Windows Graphics Component vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting improper access control. It affects Windows systems where ...

CVE-2023-36598

HIGH CVSS 7.8 Oct 10, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft's WDAC ODBC Driver by exploiting a heap-based buffer overflow. It affects systems running Microsoft Wind...

CVE-2022-35755

HIGH CVSS 7.3 May 31, 2023

This vulnerability allows attackers to gain SYSTEM-level privileges on Windows systems by exploiting the Print Spooler service. It affects Windows servers and workstations where the Print Spooler serv...

CVE-2022-35757

HIGH CVSS 7.3 May 31, 2023

This vulnerability in the Windows Cloud Files Mini Filter Driver allows attackers to gain SYSTEM-level privileges on affected Windows systems. It affects Windows 10, 11, and Server versions where the ...

CVE-2022-35743

HIGH CVSS 7.8 May 31, 2023

This vulnerability allows remote code execution through the Microsoft Windows Support Diagnostic Tool (MSDT) when processing specially crafted files. Attackers can exploit this by tricking users into ...

CVE-2022-35746

HIGH CVSS 7.8 May 31, 2023

CVE-2022-35746 is an elevation of privilege vulnerability in Windows Digital Media Receiver that allows authenticated attackers to execute arbitrary code with SYSTEM privileges. This affects Windows s...

CVE-2022-35750

HIGH CVSS 7.8 May 31, 2023

CVE-2022-35750 is a Win32k elevation of privilege vulnerability in Windows that allows an authenticated attacker to gain SYSTEM-level privileges on a compromised system. This affects Windows operating...

CVE-2022-35752

HIGH CVSS 8.1 May 31, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a flaw in the Secure Socket Tunneling Protocol (SSTP) service. Attackers could gain SYSTEM-level p...

CVE-2023-21712

HIGH CVSS 8.1 Apr 27, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a flaw in the Point-to-Point Tunneling Protocol (PPTP) implementation. Attackers could gain SYSTEM...

CVE-2022-22047

HIGH CVSS 7.8 Jul 12, 2022

This vulnerability allows an attacker to gain SYSTEM-level privileges on Windows systems by exploiting a flaw in the Client Server Runtime Subsystem (CSRSS). It affects Windows 10, 11, and Server 2019...

CVE-2022-30190

HIGH CVSS 7.8 Jun 1, 2022

This vulnerability allows remote code execution when Microsoft Support Diagnostic Tool (MSDT) is invoked via URL protocol from applications like Microsoft Word. Attackers can execute arbitrary code wi...

CVE-2022-26925

HIGH CVSS 8.1 May 10, 2022

CVE-2022-26925 is a Windows Local Security Authority (LSA) spoofing vulnerability that allows an authenticated attacker to impersonate any user on a domain controller, potentially gaining elevated pri...

CVE-2022-21999

HIGH CVSS 7.8 Feb 9, 2022

This vulnerability allows attackers to gain SYSTEM-level privileges on Windows systems by exploiting the Print Spooler service. It affects Windows servers and workstations where the Print Spooler serv...

CVE-2022-21971

HIGH CVSS 7.8 Feb 9, 2022

CVE-2022-21971 is a remote code execution vulnerability in Windows Runtime that allows attackers to execute arbitrary code on affected systems. It affects Windows 10, Windows 11, and Windows Server 20...

CVE-2022-21919

HIGH CVSS 7.0 Jan 11, 2022

CVE-2022-21919 is an elevation of privilege vulnerability in the Windows User Profile Service that allows an authenticated attacker to gain SYSTEM-level privileges on affected systems. It affects Wind...

CVE-2022-21882

HIGH CVSS 7.0 Jan 11, 2022

CVE-2022-21882 is a Win32k elevation of privilege vulnerability in Windows that allows authenticated attackers to gain SYSTEM privileges. This affects Windows operating systems where an attacker with ...

CVE-2021-41357

HIGH CVSS 7.8 Oct 13, 2021

CVE-2021-41357 is a Win32k elevation of privilege vulnerability in Windows that allows authenticated attackers to gain SYSTEM-level privileges on affected systems. This affects Windows 10, Windows 11,...

CVE-2021-40449

HIGH CVSS 7.8 Oct 13, 2021

CVE-2021-40449 is a use-after-free vulnerability in the Win32k graphics driver component of Windows. It allows a local authenticated attacker to execute arbitrary code with SYSTEM privileges, leading ...

CVE-2021-36955

HIGH CVSS 7.8 Sep 15, 2021

This vulnerability in the Windows Common Log File System Driver allows attackers to gain SYSTEM-level privileges on affected systems. It affects Windows 10 and Windows Server systems where an attacker...

CVE-2021-34486

HIGH CVSS 7.8 Aug 12, 2021

This vulnerability allows attackers to gain SYSTEM-level privileges on Windows systems by exploiting a use-after-free bug in Windows Event Tracing. It affects Windows 10, Windows Server 2016, and late...

CVE-2021-31979

HIGH CVSS 7.8 Jul 14, 2021

This is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM privileges. It affects Windows operating systems and requires an...

CVE-2021-31956

HIGH CVSS 7.8 Jun 8, 2021

CVE-2021-31956 is a Windows NTFS elevation of privilege vulnerability that allows authenticated attackers to gain SYSTEM-level privileges on affected systems. This affects Windows operating systems wi...

CVE-2024-38256

MEDIUM CVSS 5.5 Sep 10, 2024

This Windows kernel-mode driver vulnerability allows attackers to read sensitive kernel memory information. It affects Windows systems with the vulnerable driver component. Attackers could leverage th...