NIST 800-53 r5 · Controls catalogue · Family SC
SC-4Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (29)
- T1020.001 Traffic Duplication Exfiltration
- T1040 Network Sniffing Credential Access, Discovery
- T1070 Indicator Removal Stealth
- T1070.008 Clear Mailbox Data Stealth
- T1080 Taint Shared Content Lateral Movement
- T1119 Automated Collection Collection
- T1530 Data from Cloud Storage Collection
- T1552 Unsecured Credentials Credential Access
- T1552.001 Credentials In Files Credential Access
- T1552.002 Credentials in Registry Credential Access
- T1552.004 Private Keys Credential Access
- T1557 Adversary-in-the-Middle Credential Access, Collection
- T1557.002 ARP Cache Poisoning Credential Access, Collection
- T1558 Steal or Forge Kerberos Tickets Credential Access
- T1558.002 Silver Ticket Credential Access
- T1558.003 Kerberoasting Credential Access
- T1558.004 AS-REP Roasting Credential Access
- T1558.005 Ccache Files Credential Access
- T1564.009 Resource Forking Stealth
- T1565 Data Manipulation Impact
- T1565.001 Stored Data Manipulation Impact
- T1565.002 Transmitted Data Manipulation Impact
- T1565.003 Runtime Data Manipulation Impact
- T1595.003 Wordlist Scanning Reconnaissance
- T1602 Data from Configuration Repository Collection
- T1602.001 SNMP (MIB Dump) Collection
- T1602.002 Network Device Configuration Dump Collection
- T1685.005 Clear Windows Event Logs Defense Impairment
- T1685.006 Clear Linux or Mac System Logs Defense Impairment
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-404 | Improper Resource Shutdown or Release | 800+ | Requires proper shutdown/release procedures that include overwriting or isolating data to block unintended transfer via reused system objects. |
CWE-665 | Improper Initialization | 400+ | Ensures shared resources are explicitly initialized or cleared on allocation, preventing exposure of prior contents to new users or processes. |
CWE-459 | Incomplete Cleanup | 200+ | Mandates complete sanitization during cleanup so that shared resources (memory, caches, buffers) do not retain data across subjects. |
CWE-226 | Sensitive Information in Resource Not Removed Before Reuse | 36 | Directly requires removal of sensitive data from resources before reuse or reallocation to another subject, eliminating residual information transfer. |
CWE-244 | Improper Clearing of Heap Memory Before Release ('Heap Inspection') | 21 | Forces clearing of heap memory contents prior to release, preventing subsequent processes from inspecting prior sensitive data. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2026-20349 KEV | 8.8 | 8.6 | 0.0102 | good |
CVE-2024-1739 UPD | 6.9 | 9.1 | 0.0056 | partial |
CVE-2025-26304 UPD | 6.2 | 8.2 | 0.0038 | good |
CVE-2025-26305 UPD | 6.2 | 8.2 | 0.0038 | good |
CVE-2026-20039 UPD | 6.2 | 8.6 | 0.0036 | good |
CVE-2024-1902 UPD | 5.8 | 7.5 | 0.0039 | partial |
CVE-2025-36118 UPD | 5.8 | 7.5 | 0.0036 | good |
CVE-2025-70873 UPD | 5.8 | 7.5 | 0.0030 | good |
CVE-2025-5105 UPD | 5.7 | 7.3 | 0.0042 | good |
CVE-2024-4254 UPD | 5.5 | 7.1 | 0.0047 | good |
CVE-2023-42667 UPD | 5.4 | 7.8 | 0.0024 | good |
CVE-2023-49141 UPD | 5.4 | 7.8 | 0.0029 | good |
CVE-2026-12250 | 5.3 | 7.9 | 0.0011 | good |
CVE-2026-77584 | 5.2 | 7.0 | 0.0018 | partial |
CVE-2025-45663 | 5.1 | 6.5 | 0.0034 | good |
CVE-2025-5452 UPD | 5.0 | 6.6 | 0.0029 | good |
CVE-2026-56132 | 5.0 | 6.9 | 0.0011 | partial |
CVE-2024-6657 UPD | 4.9 | 6.5 | 0.0020 | partial |
CVE-2023-31325 UPD | 4.9 | 7.2 | 0.0014 | good |
CVE-2026-21919 UPD | 4.9 | 6.5 | 0.0023 | partial |
CVE-2025-36083 | 4.6 | 6.2 | 0.0012 | good |
CVE-2025-1721 | 4.6 | 5.9 | 0.0030 | good |
CVE-2025-1719 | 4.6 | 5.9 | 0.0035 | good |
CVE-2025-1722 | 4.6 | 5.9 | 0.0035 | good |
CVE-2025-33101 | 4.5 | 5.9 | 0.0020 | good |