Impact
The vulnerability arises from an incorrect type conversion or cast within the Windows Notification subsystem. An attacker who has local access and can generate or manipulate notifications can trigger this flaw and elevate privileges on the affected Windows system, as identified by CWE‑704.
Affected Systems
Affected are Microsoft Windows 10 variants 1607, 1809, 21H2 and 22H2; Windows 11 releases 24H2, 25H2 and 26H1; and Windows Server editions 2016, 2019, 2022 and 2025, including both full installations and Server Core editions. Both 32‑bit and 64‑bit implementations are impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability has not been listed in the CISA KEV catalog. Exploitation requires a local attacker with the ability to create or modify notifications; no remote attack vector is documented, limiting risk to environments where privileged users can trigger the flaw.
OpenCVE Enrichment