CWE-591

Sensitive Data Storage in Improperly Locked Memory

Parent: CWE-413 - Improper Resource Locking

The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.

77 vulnerabilities with CWE-591
CVE-2025-11711 MEDIUM
Firefox <144 - XSS
CVSS 6.5
CVE-2025-48819 HIGH
Windows UPnP Device Host - Privilege Escalation
CVSS 7.1
CVE-2025-30394 MEDIUM
Remote Desktop Gateway Service - DoS
CVSS 5.9
CVE-2025-27732 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20978 - Improper Locking
CVSS 7.0
CVE-2025-27484 HIGH
Windows UPnP Device Host - Privilege Escalation
CVSS 7.5
CVE-2025-27482 HIGH
Remote Desktop Gateway Service - Memory Corruption
CVSS 8.1
CVE-2025-27475 HIGH
Windows Update Stack - Privilege Escalation
CVSS 7.0
CVE-2025-27471 MEDIUM
Microsoft Streaming Service - DoS
CVSS 5.9
CVE-2025-26686 HIGH
Windows TCP/IP < - Memory Corruption
CVSS 7.5
CVE-2025-26671 HIGH
Microsoft Windows Server 2008 < 10.0.14393.7969 - Use After Free
CVSS 8.1
CVE-2025-26665 HIGH
Windows upnphost.dll - Privilege Escalation
CVSS 7.0
CVE-2025-26648 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2025-24045 HIGH
Windows Remote Desktop Services - Memory Corruption
CVSS 8.1
CVE-2025-24035 HIGH
Windows Remote Desktop Services - Memory Corruption
CVSS 8.1
CVE-2025-21309 HIGH
Microsoft Windows Server 2012 - Remote Code Execution
CVSS 8.1
CVE-2025-21294 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20890 - Remote Code Execution
CVSS 8.1
CVE-2025-21224 HIGH
Microsoft Windows 10 21h2 < 10.0.19044.5371 - Remote Code Execution
CVSS 8.1
CVE-2024-49132 HIGH
Microsoft Windows 10 1809 < 10.0.17763.6659 - Race Condition
CVSS 8.1
CVE-2024-49128 HIGH
Microsoft Windows Server 2012 < 10.0.14393.7606 - Race Condition
CVSS 8.1
CVE-2024-49126 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20857 - Race Condition
CVSS 8.1
CVE-2024-49123 HIGH
Microsoft Windows 10 1809 < 10.0.17763.6659 - Race Condition
CVSS 8.1
CVE-2024-49115 HIGH
Microsoft Windows Server 2016 < 10.0.14393.7606 - Race Condition
CVSS 8.1
CVE-2024-49108 HIGH
Microsoft Windows Server 2016 < 10.0.14393.7606 - Race Condition
CVSS 8.1
CVE-2024-49106 HIGH
Microsoft Windows Server 2016 < 10.0.14393.7606 - Race Condition
CVSS 8.1
CVE-2024-49097 HIGH
Microsoft Windows 10 1809 < 10.0.17763.6659 - Race Condition
CVSS 7.0
Details
Vulnerabilities 77