CVE-2020-0638
Microsoft Update Notification Manager Privilege Escalation Vulnerability
CVSS
7.8
High
EPSS
3.0%
p87
KEV
YES
May 23, 2022
Exploit Today
76
0-100
Published: Jan 14, 2020 · Last modified: Aug 12, 2026 · CWE-59
Product
Microsoft / Update Notification Manager
Vulnerability
Microsoft Update Notification Manager Privilege Escalation Vulnerability
Added to KEV
May 23, 2022
Remediate by
Jun 13, 2022
Known ransomware use
Yes
Summary description
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2020-0638
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.
- portal.msrc.microsoft.comhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0638
- portal.msrc.microsoft.comhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0638
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0638