ZeroHour

CVE-2020-0638

KEV ransomwaremass1

Local Privilege Escalation in Microsoft Update Notification Manager (Windows 10/Server)

CISA: Microsoft Update Notification Manager Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p87
Published
()
KEV added
AI analysis

CVE-2020-0638 is a local elevation of privilege flaw in the way Microsoft's Update Notification Manager handles files (CWE-59, a link-following/race-condition class of bug), affecting Windows 10 versions 1709, 1803, 1809, 1903 and 1909, plus Windows Server 1803, 1903, 1909 and 2019. To trigger it, an attacker must first gain code execution on the victim system with limited privileges; no user interaction is required after that initial foothold. Successful exploitation allows the attacker to elevate privileges with high impact on confidentiality, integrity and availability, making it a useful step in ransomware and other intrusion chains to take full control of a host. Microsoft fixed the issue in its January 2020 Patch Tuesday security updates. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-05-23 with known ransomware use, confirming exploitation in the wild; no public proof-of-concept is known.

What to do: Apply Microsoft's January 2020 security updates (or any later cumulative update) to all affected Windows 10 and Windows Server systems, prioritizing user workstations and servers where an attacker with an existing foothold would matter; federal agencies must patch per CISA KEV/BOD 22-01 timelines. Inventory endpoints still running Windows 10 builds 1709–1909 and Windows Server 1803/1903/1909/2019 and verify the installed cumulative update level. Because exploitation requires prior code execution, pair patching with EDR and least-privilege controls to disrupt ransomware chains.

Affected
Microsoft Windows 101709, 1803, 1809, 1903, 1909
Microsoft Windows Server (Semi-Annual Channel)1803, 1903, 1909
Microsoft Windows Server 20192019
Estimated exposure
mass≈100M+ Windows endpoints and servers (Windows 10 install base; affected builds were mainstream versions at disclosure) — Estimated from Windows 10's global install base of hundreds of millions of devices and widespread enterprise deployment of Windows Server 2019 and semi-annual-channel builds, with the current count of still-unpatched systems unknown but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Update Notification Manager
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows server 1803, windows server 1903, windows server 1909, windows server 2019
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news