Junglewise Threat Intelligence

CVE-2026-42970: Microsoft Windows Push Notifications information disclosure

CVE-2026-42970 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Microsoft Windows Push Notifications. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Push Notifications service, which handles app alerts and updates. An authorized user on a system could exploit this flaw to access sensitive information that should otherwise be protected. This could lead to the exposure of private data or system details to unauthorized individuals already logged into the machine.

Technical details

This vulnerability is classified as an information disclosure (CWE-200) resulting from the use of an uninitialized resource within the Windows Push Notifications component. An attacker with local access and low privileges can exploit this flaw without any user interaction. By triggering the vulnerability, the attacker can read sensitive data from memory that was not properly cleared or initialized. Microsoft has addressed this issue in their June 2026 security updates.

Affected products

  • Microsoft Windows Push Notifications

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats