Impact
The vulnerability is a use‑after‑free flaw in the Windows Push Notifications component that permits an attacker who already has local user access to acquire higher privileges. Exploitation could allow the attacker to skip the normal privilege checks and gain the rights of a system or administrator, potentially enabling further attacks on the device. The weakness falls under the CWE‑416 category, indicating a use‑after‑free defect.
Affected Systems
The flaw affects multiple Microsoft Windows releases, including Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server editions 2016, 2019, 2022, and 2025, both standard and core installations.
Risk and Exploitability
The CVSS score of 7 suggests a medium to high severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the current public exploitation likelihood appears limited. Nonetheless, the flaw requires local access, meaning that any user able to interact with the system could potentially exploit it. The attack vector is inferred to be local, leveraging an authorized user’s access to trigger the use‑after‑free condition within the notification service.
OpenCVE Enrichment