CWE-591
Sensitive Data Storage in Improperly Locked Memory
Description
The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (77)
page 3 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-48819 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2025-27732 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27475 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-26665 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-49097 | Hig | 0.46 | 7.0 | 0.00 | Dec 12, 2024 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | ||
| CVE-2024-49095 | Hig | 0.46 | 7.0 | 0.00 | Dec 12, 2024 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | ||
| CVE-2024-38137 | Hig | 0.46 | 7.0 | 0.00 | Aug 13, 2024 | Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | ||
| CVE-2024-26242 | Hig | 0.46 | 7.0 | 0.00 | Apr 9, 2024 | Windows Telephony Server Elevation of Privilege Vulnerability | ||
| CVE-2024-26236 | Hig | 0.46 | 7.0 | 0.00 | Apr 9, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2024-21405 | Hig | 0.46 | 7.0 | 0.00 | Feb 13, 2024 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | ||
| CVE-2024-21355 | Hig | 0.46 | 7.0 | 0.00 | Feb 13, 2024 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | ||
| CVE-2023-36403 | Hig | 0.46 | 7.0 | 0.01 | Nov 14, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-38159 | Hig | 0.46 | 7.0 | 0.06 | Oct 10, 2023 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2023-35360 | Hig | 0.46 | 7.0 | 0.00 | Jul 11, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-32010 | Hig | 0.46 | 7.0 | 0.00 | Jun 14, 2023 | Windows Bus Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-24899 | Hig | 0.46 | 7.0 | 0.00 | May 9, 2023 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2023-28273 | Hig | 0.46 | 7.0 | 0.00 | Apr 11, 2023 | Windows Clip Service Elevation of Privilege Vulnerability | ||
| CVE-2023-28224 | Hig | 0.46 | 7.1 | 0.00 | Apr 11, 2023 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | ||
| CVE-2023-23414 | Hig | 0.46 | 7.1 | 0.00 | Mar 14, 2023 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | ||
| CVE-2023-23407 | Hig | 0.46 | 7.1 | 0.00 | Mar 14, 2023 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability |
- risk 0.46cvss 7.1epss 0.00
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
- risk 0.46cvss 7.0epss 0.00
Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Telephony Server Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.06
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Bus Filter Driver Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Clip Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.00
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.00
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability