ThreatCluster

Multiple Vulnerabilities Discovered in Microsoft Windows 10 Versions 1809 and 21H2

First seen 16 Jun 2026, 17:12 UTC Notcve 77% similarity 55

Article Content

Browse articles
ThreatCluster

On March 10, 2026, Microsoft disclosed multiple vulnerabilities affecting Windows 10 versions 1809 and 21H2. These include use-after-free vulnerabilities, improper authentication, and out-of-bounds read issues, allowing attackers to elevate privileges or disclose sensitive information. Specifically, vulnerabilities in the Windows Authentication Methods and Graphics Component were noted, with CVEs such as CWE-416 and CWE-200 identified. The vulnerabilities could impact both local and network security, with unauthorized actors potentially exploiting them to gain elevated access or cause denial of service. The issues affect various components, including the Windows Accessibility Infrastructure and SMB Server. As of June 16, 2026, there is no indication of active exploitation, but the vulnerabilities are significant enough to warrant immediate attention from system administrators.

Key Points: • Multiple vulnerabilities in Windows 10 versions 1809 and 21H2 disclosed on March 10, 2026. • Attackers can exploit these vulnerabilities to elevate privileges or disclose sensitive information. • No active exploitation reported as of June 16, 2026, but immediate attention is advised.

ThreatCluster AI How this analysis works

Timeline

2026-03-10
Multiple vulnerabilities disclosed
Microsoft reported several vulnerabilities in Windows 10 versions 1809 and 21H2, including use-after-free and improper authentication issues.
Notcve
2026-03-10
CWE-416 identified
Use-after-free vulnerabilities in Windows Authentication Methods and Graphics Component were highlighted, allowing privilege escalation.
Notcve
2026-03-10
CWE-200 identified
Exposure of sensitive information vulnerabilities in Windows Accessibility Infrastructure and Shell Link Processing were reported.
Notcve
2026-06-16
Current status update
As of today, no active exploitation of the disclosed vulnerabilities has been reported, but they remain a concern for system administrators.
Notcve

Community

Browse all →

Tracked Entities in This Story