CWE-591— Sensitive Data Storage in Improperly Locked Memory
The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.— MITRE CWE catalog
77 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-591page 1 of 2
- CVE-2024-38106CRITICALCVSS 7.0EG 9.0⚠ KEV2024-08-13
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-28229CRITICALCVSS 7.0EG 9.0⚠ KEV2023-04-11
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- CVE-2024-38131HIGHCVSS 8.8EG 8.82024-08-13
Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
- CVE-2025-27482HIGHCVSS 8.1EG 8.12025-04-08
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
- CVE-2025-26671HIGHCVSS 8.1EG 8.12025-04-08
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2025-24045HIGHCVSS 8.1EG 8.12025-03-11
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2025-24035HIGHCVSS 8.1EG 8.12025-03-11
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2025-21309HIGHCVSS 8.1EG 8.12025-01-14
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2025-21294HIGHCVSS 8.1EG 8.12025-01-14
Microsoft Digest Authentication Remote Code Execution Vulnerability
- CVE-2025-21224HIGHCVSS 8.1EG 8.12025-01-14
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
- CVE-2024-49132HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49128HIGHCVSS 8.1EG 8.12024-12-12
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2024-49126HIGHCVSS 8.1EG 8.12024-12-12
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
- CVE-2024-49123HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49115HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49108HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49106HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2023-28283HIGHCVSS 8.1EG 8.12023-05-09
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- CVE-2023-28220HIGHCVSS 8.1EG 8.12023-04-11
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-28219HIGHCVSS 8.1EG 8.12023-04-11
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-21548HIGHCVSS 8.1EG 8.12023-01-10
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2023-21546HIGHCVSS 8.1EG 8.12023-01-10
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- CVE-2023-21535HIGHCVSS 8.1EG 8.12023-01-10
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2025-26648HIGHCVSS 7.8EG 7.82025-04-08
Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2024-43563HIGHCVSS 7.8EG 7.82024-10-08
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2024-21446HIGHCVSS 7.8EG 7.82024-03-12
NTFS Elevation of Privilege Vulnerability
- CVE-2024-20686HIGHCVSS 7.8EG 7.82024-01-09
Win32k Elevation of Privilege Vulnerability
- CVE-2023-35362HIGHCVSS 7.8EG 7.82023-07-11
Windows Clip Service Elevation of Privilege Vulnerability
- CVE-2023-35340HIGHCVSS 7.8EG 7.82023-07-11
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- CVE-2023-24946HIGHCVSS 7.8EG 7.82023-05-09
Windows Backup Service Elevation of Privilege Vulnerability
- CVE-2023-28236HIGHCVSS 7.8EG 7.82023-04-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2025-27484HIGHCVSS 7.5EG 7.52025-04-08
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
- CVE-2025-26686HIGHCVSS 7.5EG 7.52025-04-08
Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- CVE-2024-38262HIGHCVSS 7.5EG 7.52024-10-08
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2024-38263HIGHCVSS 7.5EG 7.52024-09-10
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2023-36005HIGHCVSS 7.5EG 7.52023-12-12
Windows Telephony Server Elevation of Privilege Vulnerability
- CVE-2023-35309HIGHCVSS 7.5EG 7.52023-07-11
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-33163HIGHCVSS 7.5EG 7.52023-07-11
Windows Network Load Balancing Remote Code Execution Vulnerability
- CVE-2023-28238HIGHCVSS 7.5EG 7.52023-04-11
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- CVE-2024-49091HIGHCVSS 7.2EG 7.22024-12-12
Windows Domain Name Service Remote Code Execution Vulnerability
- CVE-2025-48819HIGHCVSS 7.1EG 7.12025-07-08
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
- CVE-2023-28224HIGHCVSS 7.1EG 7.12023-04-11
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
- CVE-2023-23414HIGHCVSS 7.1EG 7.12023-03-14
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
- CVE-2023-23407HIGHCVSS 7.1EG 7.12023-03-14
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
- CVE-2025-27732HIGHCVSS 7.0EG 7.02025-04-08
Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- CVE-2025-27475HIGHCVSS 7.0EG 7.02025-04-08
Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- CVE-2025-26665HIGHCVSS 7.0EG 7.02025-04-08
Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.
- CVE-2024-49097HIGHCVSS 7.0EG 7.02024-12-12
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- CVE-2024-49095HIGHCVSS 7.0EG 7.02024-12-12
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- CVE-2024-38137HIGHCVSS 7.0EG 7.02024-08-13
Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-591 to your infrastructure
EchelonGraph correlates every CVE — across CWE-591 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →