CVE-2025-59209

Severity
5.5MEDIUM
EPSS
0.1%
top 79.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages31 packages

CVEListV5microsoft/windows_server_2012_(server_core_installation)6.2.9200.06.2.9200.25722
CVEListV5microsoft/windows_server_2016_(server_core_installation)10.0.14393.010.0.14393.8519
CVEListV5microsoft/windows_server_2019_(server_core_installation)10.0.17763.010.0.17763.7919
CVEListV5microsoft/windows_server_2025_(server_core_installation)10.0.26100.010.0.26100.6899
CVEListV5microsoft/windows_server_2012_r2_(server_core_installation)6.3.9600.06.3.9600.22824

🔴Vulnerability Details

2
CVEList
Windows Push Notification Information Disclosure Vulnerability2025-10-14
GHSA
GHSA-prq9-rc8v-364r: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information loc2025-10-14

📋Vendor Advisories

1
Microsoft
Windows Push Notification Information Disclosure Vulnerability2025-10-14
CVE-2025-59209 (MEDIUM CVSS 5.5) | Exposure of sensitive information t | cvebase.io