cbcvebase.
CVE-2025-50155
published 2025-08-12

CVE-2025-50155: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
34.9th percentile
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2110010.0.10240.21100
microsoftwindows_10_1607< 10.0.14393.833010.0.14393.8330
microsoftwindows_10_1809< 10.0.17763.767810.0.17763.7678
microsoftwindows_10_21h2< 10.0.19044.621610.0.19044.6216
microsoftwindows_10_22h2< 10.0.19045.621610.0.19045.6216
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2110010.0.10240.21100
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.833010.0.14393.8330
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.767810.0.17763.7678
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.621610.0.19044.6216
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.621610.0.19045.6216
microsoftwindows_11_22h2< 10.0.22621.576810.0.22621.5768
microsoftwindows_11_23h2< 10.0.22631.576810.0.22631.5768
microsoftwindows_11_24h2< 10.0.26100.485110.0.26100.4851
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.576810.0.22621.5768
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.576810.0.22631.5768
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.576810.0.22631.5768
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.494610.0.26100.4946
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.256226.2.9200.25622
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.227256.3.9600.22725
microsoftwindows_server_2016< 10.0.14393.833010.0.14393.8330
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.833010.0.14393.8330
microsoftwindows_server_2019< 10.0.17763.767810.0.17763.7678
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.767810.0.17763.7678
microsoftwindows_server_2022< 10.0.20348.398910.0.20348.3989

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.