CWE-591— Sensitive Data Storage in Improperly Locked Memory
The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.— MITRE CWE catalog
77 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-591page 2 of 2
- CVE-2024-26242HIGHCVSS 7.0EG 7.02024-04-09
Windows Telephony Server Elevation of Privilege Vulnerability
- CVE-2024-26236HIGHCVSS 7.0EG 7.02024-04-09
Windows Update Stack Elevation of Privilege Vulnerability
- CVE-2024-21405HIGHCVSS 7.0EG 7.02024-02-13
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
- CVE-2024-21355HIGHCVSS 7.0EG 7.02024-02-13
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
- CVE-2023-36403HIGHCVSS 7.0EG 7.02023-11-14
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-38159HIGHCVSS 7.0EG 7.02023-10-10
Windows Graphics Component Elevation of Privilege Vulnerability
- CVE-2023-35360HIGHCVSS 7.0EG 7.02023-07-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-32010HIGHCVSS 7.0EG 7.02023-06-14
Windows Bus Filter Driver Elevation of Privilege Vulnerability
- CVE-2023-24899HIGHCVSS 7.0EG 7.02023-05-09
Windows Graphics Component Elevation of Privilege Vulnerability
- CVE-2023-28273HIGHCVSS 7.0EG 7.02023-04-11
Windows Clip Service Elevation of Privilege Vulnerability
- CVE-2023-23393HIGHCVSS 7.0EG 7.02023-03-14
Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
- CVE-2023-21771HIGHCVSS 7.0EG 7.02023-01-10
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
- CVE-2023-21739HIGHCVSS 7.0EG 7.02023-01-10
Windows Bluetooth Driver Elevation of Privilege Vulnerability
- CVE-2023-35346MEDIUMCVSS 6.6EG 6.62023-07-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-35345MEDIUMCVSS 6.6EG 6.62023-07-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-35344MEDIUMCVSS 6.6EG 6.62023-07-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-35310MEDIUMCVSS 6.6EG 6.62023-07-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-28278MEDIUMCVSS 6.6EG 6.62023-04-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-28256MEDIUMCVSS 6.6EG 6.62023-04-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-28255MEDIUMCVSS 6.6EG 6.62023-04-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2025-11711MEDIUMCVSS 6.5EG 6.52025-10-14
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
- CVE-2024-43633MEDIUMCVSS 6.5EG 6.52024-11-12
Windows Hyper-V Denial of Service Vulnerability
- CVE-2025-30394MEDIUMCVSS 5.9EG 5.92025-05-13
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
- CVE-2025-27471MEDIUMCVSS 5.9EG 5.92025-04-08
Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.
- CVE-2024-38264MEDIUMCVSS 5.9EG 5.92024-11-12
Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability
- CVE-2024-34525MEDIUMCVSS 5.3EG 5.32024-05-06
FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.
- CVE-2023-21766MEDIUMCVSS 4.7EG 4.72023-01-10
Windows Overlay Filter Information Disclosure Vulnerability
Map vulnerabilities like CWE-591 to your infrastructure
EchelonGraph correlates every CVE — across CWE-591 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →