Impact
This vulnerability is a heap-based buffer overflow in the Windows Push Notifications component, classified as CWE‑122. It allows an authorized local user to trigger memory corruption that can result in privilege escalation, giving the attacker higher rights on the affected system.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations where applicable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires local, authorized access, making the attack vector an insider or compromised user. Once exploited, the attacker achieves elevated privileges on the local machine.
OpenCVE Enrichment