Impact
The vulnerability exposes sensitive information from Windows Push Notifications to an unauthorized actor, allowing an authorized local attacker to disclose that data. This results in information leakage. The weakness is a CWE‑200 problem because sensitive data is insufficiently protected.
Affected Systems
The flaw affects multiple Microsoft Windows releases, including Windows 10 version 1607 through 22H2, Windows 11 versions 23H2 to 26H1, and Windows Server editions 2016, 2019, 2022, and 2025. All architectures – x86, x64, ARM64 – are impacted as indicated by the corresponding CPE entries.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must have authorized access to a user account that can receive push notifications. No remote execution or elevation is required, so exploitation is confined to the local environment.
OpenCVE Enrichment