Impact
The vulnerability involves an uninitialized resource in Windows Push Notification handling that allows an authorized local user to glean internal data. This flaw enables local disclosure of sensitive information, potentially leading to privacy breaches and the groundwork for further local attacks. The weakness falls under CWE-908.
Affected Systems
The flaw affects several Microsoft Windows releases, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, across all listed architectures and both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity level. No EPSS score is available, so the current exploitation probability cannot be quantified. The attack vector is local and requires an authorized user, limiting the immediate reach of the flaw. However, an attacker who already has local access could use it to obtain additional system details, potentially moving toward privilege escalation or reconnaissance. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation.
OpenCVE Enrichment