Impact
The vulnerability allows an attacker who already has authorized local access to obtain sensitive information through the Windows Push Notification Service. The flaw occurs because the service does not properly safeguard notification payload data, resulting in exposure of confidential data. This is a CWE-200 Information Exposure weakness that can lead to local information disclosure.
Affected Systems
Affected editions include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2019 (both standard and Server Core), 2022, and 2025 (both standard and Server Core).
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector is inferred to be local: an attacker with privileged access to the system's notification framework can exploit the flaw, but it does not provide remote access or privilege escalation.
OpenCVE Enrichment