Executive brief
A security vulnerability exists in the Windows Push Notification service, which handles real-time alerts and updates for applications. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should be protected. This could lead to the exposure of private data or system details, though it does not allow the attacker to take control of the machine or delete files.
Technical details
An information disclosure vulnerability exists in the Windows Push Notification component due to the use of uninitialized resources. The flaw is categorized as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). To exploit this, an attacker must first gain local access to the target system with low-privileged user credentials. By interacting with the vulnerable component, the attacker can trigger the leak of sensitive data from memory. Microsoft has released security updates to address this issue, and there are no reports of exploitation in the wild at the time of publication.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory