Junglewise Threat Intelligence

CVE-2026-42971: Microsoft Windows Push Notifications information disclosure

CVE-2026-42971 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Microsoft Windows Push Notifications. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Push Notification service, which handles the delivery of alerts and updates to applications. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that they should not be able to see. This could lead to the exposure of private data or system details, though it cannot be used to take over the computer or crash the system directly.

Technical details

A vulnerability classified as CWE-200 (Exposure of Sensitive Information) exists in the Windows Push Notification component due to the use of an uninitialized resource. An attacker with local access and low privileges can exploit this flaw without any user interaction. By triggering the vulnerability, the attacker can read data from memory that was not properly cleared, potentially leading to the disclosure of sensitive system or user information. Microsoft has released security updates to address this issue, and the exploit is currently limited to local information disclosure (Confidentiality: High) without impacting Integrity or Availability.

Affected products

  • Microsoft Windows Push Notifications

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats