CWE-591
Sensitive Data Storage in Improperly Locked Memory
Description
The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (77)
page 4 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23393 | Hig | 0.46 | 7.0 | 0.00 | Mar 14, 2023 | Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability | ||
| CVE-2023-21771 | Hig | 0.46 | 7.0 | 0.00 | Jan 10, 2023 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | ||
| CVE-2023-21739 | Hig | 0.46 | 7.0 | 0.01 | Jan 10, 2023 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-35346 | Med | 0.43 | 6.6 | 0.01 | Jul 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-35345 | Med | 0.43 | 6.6 | 0.01 | Jul 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-35344 | Med | 0.43 | 6.6 | 0.01 | Jul 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-35310 | Med | 0.43 | 6.6 | 0.01 | Jul 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-28278 | Med | 0.43 | 6.6 | 0.01 | Apr 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-28256 | Med | 0.43 | 6.6 | 0.01 | Apr 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-28255 | Med | 0.43 | 6.6 | 0.01 | Apr 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2025-11711 | Med | 0.42 | 6.5 | 0.00 | Oct 14, 2025 | There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | ||
| CVE-2024-43633 | Med | 0.42 | 6.5 | 0.01 | Nov 12, 2024 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2025-30394 | Med | 0.40 | 5.9 | 0.30 | May 13, 2025 | Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-27471 | Med | 0.38 | 5.9 | 0.01 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network. | ||
| CVE-2024-38264 | Med | 0.38 | 5.9 | 0.01 | Nov 12, 2024 | Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability | ||
| CVE-2024-34525 | Med | 0.34 | 5.3 | 0.00 | May 6, 2024 | FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file. | ||
| CVE-2023-21766 | Med | 0.31 | 4.7 | 0.01 | Jan 10, 2023 | Windows Overlay Filter Information Disclosure Vulnerability |
- risk 0.46cvss 7.0epss 0.00
Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Bluetooth Driver Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.42cvss 6.5epss 0.00
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
- risk 0.42cvss 6.5epss 0.01
Windows Hyper-V Denial of Service Vulnerability
- risk 0.40cvss 5.9epss 0.30
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
- risk 0.38cvss 5.9epss 0.01
Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.
- risk 0.38cvss 5.9epss 0.01
Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability
- risk 0.34cvss 5.3epss 0.00
FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.
- risk 0.31cvss 4.7epss 0.01
Windows Overlay Filter Information Disclosure Vulnerability