Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SI

SI-16Memory Protection

Implement the following controls to protect the system memory from unauthorized code execution: {{ insert: param, si-16_odp }}.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (36)

Weaknesses this control addresses (5)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-787Out-of-bounds Write16,279Out-of-bounds writes that corrupt control flow or inject shellcode are rendered non-executable by the same memory protections.
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer14,126Memory protections (e.g., W^X, ASLR) make exploitation of buffer-boundary violations far harder to turn into code execution.
CWE-416Use After Free8,528Use-after-free exploits that achieve arbitrary code execution are blocked or significantly hardened by non-executable pages and ASLR.
CWE-94Improper Control of Generation of Code ('Code Injection')6,628Directly prevents execution of attacker-supplied code written into data memory regions.
CWE-123Write-what-where Condition50Write-what-where primitives are neutralized when the attacker cannot execute the memory they control.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-24085 KEV5.010.00.1590good
CVE-2025-24201 KEV4.010.00.0024good
CVE-2025-31277 KEV3.88.80.0017good
CVE-2025-43510 KEV3.67.80.0030good
CVE-2025-43520 KEV3.15.50.0027good
CVE-2025-241183.07.10.2702good
CVE-2022-509222.09.80.0026good
CVE-2025-242112.09.80.0077good
CVE-2025-299132.09.80.0076good
CVE-2025-260042.09.80.0060good
CVE-2025-242692.09.80.0045good
CVE-2024-554142.09.80.0009good
CVE-2025-256642.09.80.0009good
CVE-2020-371762.09.80.0008good
CVE-2020-371242.09.80.0008good
CVE-2025-341932.09.80.0029good
CVE-2025-431862.09.80.0027good
CVE-2025-431892.09.80.0014good
CVE-2025-505182.09.80.0012good
CVE-2025-525791.99.40.0020good
CVE-2026-244061.88.80.0014good
CVE-2026-348651.89.10.0003good
CVE-2026-405721.89.00.0001good
CVE-2024-545431.88.80.0014good
CVE-2025-03041.88.80.0008good

Other controls in family SI

SI-1 SI-10 SI-11 SI-12 SI-13 SI-14 SI-15 SI-17 SI-18 SI-19 SI-2 SI-20 SI-21 SI-22 SI-23 SI-3 SI-4 SI-5 SI-6 SI-7 SI-8 SI-9