Impact
The flaw lies in the Windows Push Notification infrastructure where locally authorized users can invoke notification components to read sensitive data that should be protected by the operating system. The weakness enables a local attacker to expose internal information, compromising confidentiality without affecting integrity or availability. This vulnerability is classified as CWE‑200, an Information Exposure weakness.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 24H2, 25H2 and 26H1; Microsoft Windows Server 2012, 2016, 2019, 2022 and 2025 including their Server Core installations. No specific build or patch level detail was supplied.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while an EPSS score of less than 1 % suggests that exploitation is unlikely under current conditions. The vulnerability is not listed in the CISA KEV catalog. Attack requires local authorized access to the target machine and the ability to trigger the push notification flow; no known path to remote code execution or privilege escalation exists.
OpenCVE Enrichment