Impact
This vulnerability originates from a use-after-free condition in Windows Notification, enabling an authorized local attacker to execute arbitrary code with elevated privileges. The flaw allows a compromised notification process to read or write memory it should not have access to, effectively granting the attacker higher privileges than the original user context they entered with. The impact is confined to local exploitation and does not enable remote code execution or data exfiltration beyond the affected host.
Affected Systems
Affected Microsoft operating systems include Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Versions 23H2, 24H2, 25H2, 26H1 (including version 23H2), Windows Server 2022, and Windows Server 2025 (both full and Server Core installations).
Risk and Exploitability
The CVSS score of 7 indicates a high severity risk. EPSS information is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated attacker with authorized access to deliver malicious notification payloads; remote attackers are precluded by the lack of a network-facing vector. Consequently, the threat is significant for organizations that allow users to trigger notifications from untrusted sources, especially where privilege escalation could lead to domain-wide compromise should local administrators be affected.
OpenCVE Enrichment