CVE-2020-0638: Microsoft Update Notification Manager Privilege Escalation Vulnerability
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.
Other sources
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0638?
CVE-2020-0638 is rated as a medium severity vulnerability.
How do I fix CVE-2020-0638?
To fix CVE-2020-0638, you should apply the latest security updates provided by Microsoft.
What versions of Windows are affected by CVE-2020-0638?
CVE-2020-0638 affects Microsoft Windows 10 versions 1709, 1803, 1809, 1903, 1909 and Windows Server versions 2016 and 2019.
What kind of attack does CVE-2020-0638 enable?
CVE-2020-0638 allows attackers to elevate privileges on the affected systems.
Is there a workaround for CVE-2020-0638?
There are no known workarounds for CVE-2020-0638; the recommended action is to apply the security updates.