CVE-2025-50155

HIGH

Windows Push Notifications - Privilege Escalation

Title source: llm
STIX 2.1

Description

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 44.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-843 CWE-122
Status published
Products (15)
microsoft/windows_10_1507 < 10.0.10240.21100 (2 CPE variants)
microsoft/windows_10_1607 < 10.0.14393.8330 (2 CPE variants)
microsoft/windows_10_1809 < 10.0.17763.7678 (2 CPE variants)
microsoft/windows_10_21h2 < 10.0.19044.6216
microsoft/windows_10_22h2 < 10.0.19045.6216
microsoft/windows_11_22h2 < 10.0.22621.5768
microsoft/windows_11_23h2 < 10.0.22631.5768
microsoft/windows_11_24h2 < 10.0.26100.4851
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
... and 5 more
Published Aug 12, 2025
Tracked Since Feb 18, 2026