Information Disclosure Vulnerability in Windows Push Notification by Microsoft
CVE-2025-59209

5.5MEDIUM

What is CVE-2025-59209?

A vulnerability in Windows Push Notification Core allows authorized attackers to gain access to sensitive information. This exposure may enable unauthorized actors to disclose sensitive data locally, potentially compromising user privacy and security. It is essential for organizations to be aware of this issue and take appropriate steps to mitigate the risk.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21161

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8519

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7919

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59209 : Information Disclosure Vulnerability in Windows Push Notification by Microsoft