Impact
The vulnerability in Windows Push Notifications exposes sensitive information to an unauthorized actor, enabling an authorized attacker to disclose that information locally.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including standard and Server Core installations.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity, while the EPSS score of <1% signals a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, further reducing the current threat level. The likely attack vector is a local user who has legitimate access to initiate the Push Notification Service; once exploitation occurs, the attacker can retrieve sensitive information that should remain confidential.
OpenCVE Enrichment