Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
History

Tue, 12 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 17:30:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Title Windows Push Notifications Apps Elevation of Privilege Vulnerability
Weaknesses CWE-122
CWE-843
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published: 2025-08-12T17:10:39.411Z

Updated: 2025-08-13T15:43:45.875Z

Reserved: 2025-06-13T18:35:16.734Z

Link: CVE-2025-50155

cve-icon Vulnrichment

Updated: 2025-08-12T20:01:59.584Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-12T18:15:32.293

Modified: 2025-08-13T17:34:12.350

Link: CVE-2025-50155

cve-icon Redhat

No data.