Impact
Use after free in the Windows Push Notification subsystem allows an attacker with access to create or modify push notifications to execute code that runs with elevated privileges. The flaw occurs when memory allocated for a notification is freed while references remain, enabling the attacker to corrupt execution flow and bypass security checks. This can lead to full system compromise by an authorized local user.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core). The issue exists in the push notification service of these operating systems.
Risk and Exploitability
The CVSS score of 7.0 classifies the vulnerability as High severity. No EPSS score is currently available and the vulnerability is not listed in CISA’s KEV catalog, indicating it has not yet been widely exploited. The likely attack vector requires an authorized local user or an application with permissions to manipulate push notifications; remote exploitation is not supported by the current description. Once the use‑after‑free is triggered, an attacker can gain privileges above the user level, thereby achieving full control of the affected machine.
OpenCVE Enrichment