CWE-591

Sensitive Data Storage in Improperly Locked Memory

Parent: CWE-413 - Improper Resource Locking

The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.

77 vulnerabilities with CWE-591
CVE-2024-49095 HIGH
Microsoft Windows 10 1809 < 10.0.17763.6659 - Race Condition
CVSS 7.0
CVE-2024-49091 HIGH
Microsoft Windows Server 2012 - Remote Code Execution
CVSS 7.2
CVE-2024-43633 MEDIUM
Microsoft Windows 11 22h2 < 10.0.22621.4460 - Denial of Service
CVSS 6.5
CVE-2024-38264 MEDIUM
Microsoft VHDX - DoS
CVSS 5.9
CVE-2024-43563 HIGH
Windows Ancillary Function Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38262 HIGH
Windows Remote Desktop < - RCE
CVSS 7.5
CVE-2024-38263 HIGH
Windows Remote Desktop < - RCE
CVSS 7.5
CVE-2024-38137 HIGH
Windows Resource Manager PSM Service Extension - Privilege Escalation
CVSS 7.0
CVE-2024-38131 HIGH
Clipboard Virtual Channel Extension - RCE
CVSS 8.8
CVE-2024-38106 HIGH KEV
Windows Kernel - Privilege Escalation
CVSS 7.0
CVE-2024-34525 MEDIUM
FileCodeBox 2.0 - Info Disclosure
CVSS 5.3
CVE-2024-26242 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20596 - Race Condition
CVSS 7.0
CVE-2024-26236 HIGH
Microsoft Windows Server 2022 23h2 < 10.0.25398.830 - Race Condition
CVSS 7.0
CVE-2024-21446 HIGH
NTFS - Privilege Escalation
CVSS 7.8
CVE-2024-21405 HIGH
Microsoft MSMQ - Privilege Escalation
CVSS 7.0
CVE-2024-21355 HIGH
Microsoft MSMQ - Privilege Escalation
CVSS 7.0
CVE-2024-20686 HIGH
Win32k - Privilege Escalation
CVSS 7.8
CVE-2023-36005 HIGH
Windows Telephony Server - Privilege Escalation
CVSS 7.5
CVE-2023-36403 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.0
CVE-2023-38159 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20232 - Race Condition
CVSS 7.0
CVE-2023-35362 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20048 - Race Condition
CVSS 7.8
CVE-2023-35360 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20048 - Race Condition
CVSS 7.0
CVE-2023-35346 MEDIUM
Microsoft Windows Server 2008 - Race Condition
CVSS 6.6
CVE-2023-35345 MEDIUM
Microsoft Windows Server 2008 - Remote Code Execution
CVSS 6.6
CVE-2023-35344 MEDIUM
Microsoft Windows Server 2008 - Remote Code Execution
CVSS 6.6
Details
Vulnerabilities 77