CWE-591
77 CVEs • Abstraction: Variant
Sensitive Data Storage in Improperly Locked Memory
The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.
CVEs (77)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunder...Show more |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Jul 8, 2025 N/A· v4 7.1 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. |
1Microsoft 6Windows Server 2012 Windows Server 2016Windows Server 2019+3 moreJun 17, 2026 May 13, 2025 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Apr 8, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Apr 8, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network. |
1Microsoft 5Windows Server 2016 Windows Server 2019Windows Server 2022+2 moreJun 17, 2026 Apr 8, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. |
1Microsoft 3Windows 11 22h2 Windows 11 23h2Windows 11 24h2Jun 17, 2026 Apr 8, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Apr 8, 2025 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Apr 8, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network. |
1Microsoft 7Windows Server 2008 Windows Server 2012Windows Server 2016+4 moreJun 17, 2026 Apr 8, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Apr 8, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Apr 8, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 6Windows Server 2012 Windows Server 2016Windows Server 2019+3 moreJun 17, 2026 Mar 11, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Mar 11, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
1Microsoft 6Windows Server 2012 Windows Server 2016Windows Server 2019+3 moreJun 17, 2026 Jan 14, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Remote Desktop Services Remote Code Execution Vulnerability |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Jan 14, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Microsoft Digest Authentication Remote Code Execution Vulnerability |
1Microsoft 8Windows 10 21h2 Windows 10 22h2Windows 11 22h2+5 moreJun 17, 2026 Jan 14, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Remote Desktop Services Remote Code Execution Vulnerability |
1Microsoft 6Windows Server 2012 Windows Server 2016Windows Server 2019+3 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability |