Impact
Use after free bug in the Windows Push Notifications component allows an authorized local user to increase privileges on a Windows system. The flaw can be triggered by manipulating the memory management of the push notification service, leading to a use after free situation that exploits attacker control to gain elevated rights. This local privilege escalation can enable an attacker to compromise the security of the machine and potentially install unauthorized software. The flaw maps to CWE‑416: Use After Free.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, Windows Server 2022, and Windows Server 2025 (including Server Core installations) are all affected by this vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the vulnerability can be exploited by an authorized local attacker. Although the EPSS score is not available, the lack of a KEV listing suggests it has not yet been publicly exploited at scale. Attackers would need local access to trigger the use‑after‑free, but once achieved, they can elevate privileges and potentially take full control of the system. Effective mitigation requires timely patching.
OpenCVE Enrichment