CWE-591

Sensitive Data Storage in Improperly Locked Memory

Parent: CWE-413 - Improper Resource Locking

The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.

77 vulnerabilities with CWE-591
CVE-2023-35340 HIGH
Windows CNG Key Isolation Service - Privilege Escalation
CVSS 7.8
CVE-2023-35310 MEDIUM
Windows DNS Server - Remote Code Execution via Race Condition
CVSS 6.6
CVE-2023-35309 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution via MSMQ Race Condition
CVSS 7.5
CVE-2023-33163 HIGH
Microsoft Windows Network Load Balancing - Remote Code Execution
CVSS 7.5
CVE-2023-32010 HIGH
Windows Bus Filter Driver - Privilege Escalation
CVSS 7.0
CVE-2023-28283 HIGH
Windows LDAP - Remote Code Execution
CVSS 8.1
CVE-2023-24946 HIGH
Windows Backup Service - Privilege Escalation
CVSS 7.8
CVE-2023-24899 HIGH
Windows Graphics Component - Privilege Escalation
CVSS 7.0
CVE-2023-28278 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Race Condition
CVSS 6.6
CVE-2023-28273 HIGH
Windows 10/11, Server 2016-2022 Elevation of Privilege via Clip Service Race Condition
CVSS 7.0
CVE-2023-28256 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution
CVSS 6.6
CVE-2023-28255 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution
CVSS 6.6
CVE-2023-28238 HIGH
Windows Internet Key Exchange (IKE) Protocol Extensions - Remote Code Execution
CVSS 7.5
CVE-2023-28236 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2023-28229 HIGH KEV
Windows CNG Key Isolation Service - Privilege Escalation
CVSS 7.0
CVE-2023-28224 HIGH
Windows PPPoE - Remote Code Execution
CVSS 7.1
CVE-2023-28220 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Layer 2 Tunneling Protocol Remote Code Execution
CVSS 8.1
CVE-2023-28219 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution via Layer 2 Tunneling Protocol
CVSS 8.1
CVE-2023-23414 HIGH
Windows PPPoE - Remote Code Execution
CVSS 7.1
CVE-2023-23407 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution via PPPoE Race Condition
CVSS 7.1
CVE-2023-23393 HIGH
Windows BrokerInfrastructure Service - Elevation of Privilege via Race Condition
CVSS 7.0
CVE-2023-21771 HIGH
Windows Local Session Manager LSM - Privilege Escalation
CVSS 7.0
CVE-2023-21766 MEDIUM
Windows Overlay Filter - Info Disclosure
CVSS 4.7
CVE-2023-21739 HIGH
Windows Bluetooth Driver - Privilege Escalation
CVSS 7.0
CVE-2023-21548 HIGH
Windows SSTP - Remote Code Execution
CVSS 8.1
Details
Vulnerabilities 77