CVE-2020-0638

Microsoft Windows, Microsoft Windows 10 Version 1903 for ARM64-based Systems, Microsoft Windows 10 Version 1903 for 32-bit Systems

Published 14 Jan 2020 · updated 12 Aug 2026 · Analyzed

7.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 23 May 2022, with a remediation deadline of 13 Jun 2022 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply updates per vendor instructions.

Description

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.

References