You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-50155
About this tag
CVE-2025-50155 is an elevation of privilege vulnerability in the Windows Push Notifications component, classified as a type confusion issue. Microsoft's Security Response Center (MSRC) has documented it as allowing an authorized local attacker to exploit the Windows Push Notifications stack to escalate privileges, potentially reaching SYSTEM-level rights. The vulnerability requires valid logon credentials on the target machine and may be combined with additional actions for full exploitation. Administrators are advised to apply vendor-supplied fixes included in appropriate cumulative updates. This tag covers discussions and guidance related to CVE-2025-50155, including its impact, attack vector, and mitigation steps for Windows systems.
Microsoft’s Security Response Center (MSRC) has cataloged CVE-2025-50155 as an Elevation of Privilege (EoP) vulnerability in the Windows Push Notifications Apps component described as “Access of resource using incompatible type (‘type confusion’).” The issue allows an authorized local attacker —...