Impact
An uninitialized resource in Windows Push Notifications can leak sensitive information. The vulnerability allows a user with authorized local access to read data that should otherwise be protected. The weakness is documented as CWE-200, highlighting inadequate information protection. The potential impact is the exposure of confidential information to a privileged local user, which could aid further attacks or compromise user privacy.
Affected Systems
The flaw affects multiple Microsoft Windows releases, including Windows 10 version 1607 through 22H2, Windows 11 versions 23H2 to 26H1, and Windows Server editions 2016, 2019, 2022, and 2025. All architectures – x86, x64, ARM64 – are impacted as indicated by the corresponding CPE entries.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, but the vulnerability does not have a publicly known exploit (EPSS score is not available). It is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is local; an attacker must have authorized access to a user account that can receive push notifications. No remote execution or elevation is required, so the risk is confined to environments where privileged users are present.
OpenCVE Enrichment