CWE-591: CWE-591

26
Total CVEs
0
Critical
26
High
7.4
Avg CVSS

Yearly Trend

2025
8
2024
4
2023
14

Top Affected Vendors

1 Microsoft 26

All CWE-591 CVEs (26)

CVE-2025-24045
8.1

This vulnerability in Windows Remote Desktop Services allows attackers to access sensitive data stored in improperly locked memory, potentially leadin...

Mar 11, 2025
CVE-2025-24035
8.1

This vulnerability in Windows Remote Desktop Services allows unauthorized attackers to execute arbitrary code over the network by exploiting improperl...

Mar 11, 2025
CVE-2025-21309
8.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Remote Desktop Services. Attackers can exploit this wi...

Jan 14, 2025
CVE-2025-21294
8.1

This vulnerability allows remote code execution via Microsoft Digest Authentication, enabling attackers to execute arbitrary code on affected systems....

Jan 14, 2025
CVE-2023-28283
8.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running LDAP services by sending specially crafted requests. I...

May 9, 2023
CVE-2023-28220
8.1

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable Layer 2 Tunneling Protocol (L2TP) implementations. ...

Apr 11, 2023
CVE-2023-24946
7.8

This vulnerability in Windows Backup Service allows authenticated attackers to gain SYSTEM-level privileges on affected systems. It affects Windows se...

May 9, 2023
CVE-2023-28236
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with kernel privileges on Windows systems. It enables local privilege es...

Apr 11, 2023
CVE-2024-38263
7.5

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Remote Desktop Licensing Service. Attackers can ex...

Sep 10, 2024
CVE-2023-35309
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows remote attackers to execute arbitrary code on affected systems by sending specially craf...

Jul 11, 2023
CVE-2023-33163
7.5

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Network Load Balancing (NLB) service. Attackers can ex...

Jul 11, 2023
CVE-2023-28238
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted packets to the Internet ...

Apr 11, 2023
CVE-2025-48819
7.1

This vulnerability in Windows Universal Plug and Play (UPnP) Device Host allows an attacker on the same network to access sensitive data stored in imp...

Jul 8, 2025
CVE-2023-28224
7.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a flaw in the Point-to-Point Protocol over Ether...

Apr 11, 2023
CVE-2023-23407
7.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by sending specially crafted PPPoE packets. It affects Windows...

Mar 14, 2023
CVE-2023-23414
7.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by sending specially crafted PPPoE packets. It affects Windows...

Mar 14, 2023
CVE-2025-27732
7.0

This vulnerability allows an authorized attacker with local access to exploit improper memory locking in Windows Win32K graphics subsystem to access s...

Apr 8, 2025
CVE-2025-27475
7.0

This vulnerability in Windows Update Stack allows local attackers with existing system access to read sensitive data from improperly locked memory, po...

Apr 8, 2025
CVE-2025-26665
7.0

This vulnerability in Windows upnphost.dll allows local attackers with valid credentials to access improperly locked memory containing sensitive data,...

Apr 8, 2025
CVE-2024-26242
7.0

CVE-2024-26242 is an elevation of privilege vulnerability in Windows Telephony Server that allows authenticated attackers to gain SYSTEM-level privile...

Apr 9, 2024
CVE-2024-21405
7.0

This vulnerability in Microsoft Message Queuing (MSMQ) allows an authenticated attacker to execute code with SYSTEM privileges on affected systems. It...

Feb 13, 2024
CVE-2024-21355
7.0

This vulnerability in Microsoft Message Queuing (MSMQ) allows an authenticated attacker to execute code with SYSTEM privileges on affected systems. It...

Feb 13, 2024
CVE-2023-36403
7.0

This Windows kernel vulnerability allows attackers to elevate privileges through race conditions in memory management. It affects Windows systems wher...

Nov 14, 2023
CVE-2023-38159
7.0

This Windows Graphics Component vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a memory...

Oct 10, 2023
CVE-2023-32010
7.0

This vulnerability in the Windows Bus Filter Driver allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting im...

Jun 14, 2023
CVE-2023-28229
7.0

This vulnerability in Windows CNG Key Isolation Service allows attackers to elevate privileges from a low-privileged user account to SYSTEM level. It ...

Apr 11, 2023

About CWE-591 (CWE-591)

Our database tracks 26 CVEs classified as CWE-591, with 0 rated critical and 26 rated high severity. The average CVSS score for CWE-591 vulnerabilities is 7.4.

External reference: View CWE-591 on MITRE CWE →

Monitor CWE-591 Vulnerabilities

Get alerted when new CWE-591 CVEs affect your infrastructure.

Start Monitoring Free