Executive brief
A security vulnerability exists in the Windows Push Notification service, which manages real-time alerts and updates for applications. An authorized user on a system could exploit this flaw to access sensitive information that should otherwise be protected. This could lead to the exposure of private data or system details to unauthorized individuals already logged into the machine.
Technical details
A vulnerability classified as CWE-908 (Use of Uninitialized Resource) exists within the Windows Push Notifications component. The flaw occurs when the system fails to properly initialize a resource before it is accessed, potentially leaving sensitive data from previous operations in memory. An attacker with local access and low-level privileges can exploit this to disclose information from the system's memory. The attack requires no user interaction and has a high impact on confidentiality, though it does not directly allow for data modification or service disruption. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Push Notifications
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory