Impact
The vulnerability originates from a race condition in the Windows Push Notification service, where concurrent access to a shared resource is not properly synchronized. This flaw can be exploited by an authenticated user on the same machine to gain higher privileges, effectively allowing local privilege escalation. The weakness is classified as a race condition (CWE-362) and a use‑after‑free (CWE-416), permitting attackers to bypass privilege checks internally.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Windows Server 2025 (Standard and Server Core) are affected. The issue resides in the Windows Push Notification infrastructure across these releases.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of < 1% shows a low expected exploitation probability. Because the flaw requires a local authorized user, the attack surface is limited to on‑premises users who can run code on the target machine. The vulnerability is not listed in the CISA KEV catalog and no publicly disclosed exploits are known.
OpenCVE Enrichment