Impact
Windows Push Notifications contains a race condition where concurrent operations on a shared resource are improperly synchronized. The flaw allows an attacker with local privileges to trigger overlapping actions that corrupt the state of the notification system, thereby elevating their own privileges to a higher level on the same machine.
Affected Systems
Microsoft Windows 10 Version 1809, 21H2, 22H2; Microsoft Windows 11 Version 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2019 (including Server Core), Windows Server 2022, Windows Server 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability. The EPSS score is not provided and the flaw is not listed in CISA KEV. An attacker who can run code with local user privileges is the most likely vector, as the race condition requires concurrent execution of the notification service. No public exploit has yet been disclosed, but the flaw can be triggered under normal system conditions.
OpenCVE Enrichment