Impact
The vulnerability allows an attacker who has legitimate local access to the system to read sensitive data that should be protected, resulting in a local information disclosure. The weakness involves improper handling of Windows Push Notification data, leading to exposure of confidential information. The weakness is classified as CWE-200. The CVE is rated with a CVSS score of 5.5, indicating a moderate impact and potential compromise of data confidentiality for users with local access.
Affected Systems
Microsoft Windows versions 10 21H2 and 22H2, Windows 11 24H2, 25H2, and 26H1, and Windows Server 2022, 2025, including Server Core installations are affected. The vulnerability is present in the push notification subsystem of these editions and applies to both x86, x64, and arm64 architectures where listed.
Risk and Exploitability
The attack requires local attacker privileges; the EPSS score is less than 1%, suggesting a very low probability of public exploitation at this time and no presence in the CISA KEV catalog. The vulnerability’s severity is moderate, and it does not provide an escalation path beyond local data disclosure. A local attacker with access could leverage the flaw to retrieve sensitive information from the push notification payload.
OpenCVE Enrichment