Impact
The vulnerability exposes sensitive information to an unauthorized actor via Windows Push Notifications. An authorized attacker can trigger a local information disclosure, potentially revealing protected data, which is a classic example of CWE‑200.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1; Microsoft Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025 and Windows Server 2025 (Server Core installation).
Risk and Exploitability
The CVSS score of 5.5 classifies this vulnerability as moderate, and the EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The vulnerability requires a local, authorized user to trigger the information disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, further suggesting that active exploitation is limited. Overall, while the impact is not catastrophic, the moderate CVSS and lack of remote exploitation imply a moderate but non‑negligible risk to affected installations.
OpenCVE Enrichment