Impact
The vulnerability arises from an uninitialized resource within the Windows Push Notification Service, enabling an authorized local user to read data that should remain protected. This leads to disclosure of potentially sensitive system information and poses a threat to confidentiality of the affected machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity. The EPSS value is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a currently low yet nonzero exploitation likelihood. The description implies a local attack vector that requires an authenticated user to invoke the Push Notification Service; once exploited, the attacker can retrieve information that should have been guarded.
OpenCVE Enrichment