Impact
Based on the updated description, this vulnerability allows the Windows Push Notification Service to expose sensitive data to an unauthorized actor, permitting an authorized attacker to disclose local information. The flaw is a classic example of CWE‑200 (Information Exposure). Because the disclosure requires local access, an attacker must be a privileged user on the machine; remote exploitation is not possible.
Affected Systems
Microsoft Windows 10 (1607, 1809, 21H2, 22H2), Microsoft Windows 11 (23H2, 24H2, 25H2, 26H1) including their Server Core installations, and Windows Server 2016, 2019, 2022, and 2025.
Risk and Exploitability
The CVSS score of 5.5 rates this flaw as moderate severity, and the EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog, suggesting it has not been widely abused. Because only local access is required, the risk is confined to users with local privileges and does not provide remote code execution or system takeover.
OpenCVE Enrichment