CWE-591
Sensitive Data Storage in Improperly Locked Memory
Description
The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (77)
page 2 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21548 | Hig | 0.53 | 8.1 | 0.01 | Jan 10, 2023 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | ||
| CVE-2023-21546 | Hig | 0.53 | 8.1 | 0.01 | Jan 10, 2023 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | ||
| CVE-2023-21535 | Hig | 0.53 | 8.1 | 0.01 | Jan 10, 2023 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | ||
| CVE-2025-26648 | Hig | 0.51 | 7.8 | 0.00 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-43563 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2024 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | ||
| CVE-2024-21446 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | NTFS Elevation of Privilege Vulnerability | ||
| CVE-2024-20686 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-36005 | Hig | 0.51 | 7.5 | 0.24 | Dec 12, 2023 | Windows Telephony Server Elevation of Privilege Vulnerability | ||
| CVE-2023-35362 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Windows Clip Service Elevation of Privilege Vulnerability | ||
| CVE-2023-35340 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | ||
| CVE-2023-24946 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | Windows Backup Service Elevation of Privilege Vulnerability | ||
| CVE-2023-28236 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2025-27484 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-26686 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2024-38262 | Hig | 0.49 | 7.5 | 0.01 | Oct 8, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | ||
| CVE-2024-38263 | Hig | 0.49 | 7.5 | 0.01 | Sep 10, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | ||
| CVE-2023-35309 | Hig | 0.49 | 7.5 | 0.01 | Jul 11, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-33163 | Hig | 0.49 | 7.5 | 0.00 | Jul 11, 2023 | Windows Network Load Balancing Remote Code Execution Vulnerability | ||
| CVE-2023-28238 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2023 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2024-49091 | Hig | 0.47 | 7.2 | 0.02 | Dec 12, 2024 | Windows Domain Name Service Remote Code Execution Vulnerability |
- risk 0.53cvss 8.1epss 0.01
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
NTFS Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.5epss 0.24
Windows Telephony Server Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Clip Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Backup Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.01
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.00
Windows Network Load Balancing Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Windows Domain Name Service Remote Code Execution Vulnerability