You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-53724
About this tag
CVE-2025-53724 is a security vulnerability in the Windows Push Notifications Apps component that leads to local privilege escalation. The flaw is caused by a type confusion condition, where the system accesses a resource using an incompatible type. A locally authenticated attacker can exploit this bug to gain elevated privileges on the affected Windows host. Microsoft has addressed this vulnerability in a security update. Discussions on WindowsForum.com cover the advisory details, the nature of the type confusion, and the potential impact on enterprise environments. Users are advised to apply the latest patches to mitigate the risk.
Microsoft’s security advisory identifies CVE-2025-53724 as an elevation of privilege vulnerability in the Windows Push Notifications Apps component that stems from an access of resource using incompatible type (type confusion); when triggered by a locally authorized user, the bug can be abused...