Microsoft Windows 10
cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*
A vulnerability in Windows Push Notifications allows an authorized attacker to disclose sensitive information locally. This issue affects several versions of Windows 10, Windows 11, Windows Server 2016, Windows Server 2025, and Windows Server 2022. The vulnerability could leak the address of a medium integrity process to a lower integrity caller process.
Exploitation of this vulnerability could lead to unauthorized information disclosure, allowing an attacker to access sensitive data from a local process.
Users can download the security update for their specific Windows version through the Microsoft Update Catalog. Security Update KB5099538 is available for Windows 10 versions 21H2, 22H2, and 1809, as well as for Windows Server 2019 and 2022. Security Update KB5099540 can be downloaded for Windows Server 2025. For Windows 11, Security Update KB5101650 is available for versions 24H2 and 25H2, while KB5095051 can be downloaded for version 26H1. Windows 11 version 26H1 for ARM64-based systems also has a corresponding security update.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.