CWE-591Variant2 in KEV

Sensitive Data Storage in Improperly Locked Memory

Draft in the CWE catalog · 75 CVEs mapped

75
CVEs mapped
2
In KEV
7.2
Median CVSS
What it is

The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.

Recent examples
7.1cvss
CVE-2025-48819

Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability

Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.

HIGHno explanation yet
0%
epss
5.9cvss
CVE-2025-30394

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

MEDIUMno explanation yet
30%
epss
7.0cvss
CVE-2025-27732

Windows Graphics Component Elevation of Privilege Vulnerability

Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-591
Abstraction
Variant
Structure
Simple
Status
Draft