Impact
The flaw stems from a race condition caused by improper synchronization of a shared resource in Windows Push Notifications, classified as CWE‑362 and CWE‑416. An attacker who is already authenticated locally can trigger the condition and elevate their permissions to a higher level, potentially enabling the execution of arbitrary code, modification of system settings, or installation of malicious software. The primary impact is therefore the acquisition of privileged rights on a local machine, not remote code execution or denial of service.
Affected Systems
Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2019, 2022, and 2025. The vulnerability affects both 32‑bit and 64‑bit builds on x86, x86_64, and arm64 architectures as identified in the Common Platform Enumeration data.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating medium to high severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation data. The attack vector requires a local authorized user; no remote access or network-based exploitation is possible. Once a privileged account is achieved, the attacker can perform any action allowed by that account, raising the risk in environments where user accounts have broad permissions. This presents a moderate threat that warrants prompt remediation.
OpenCVE Enrichment