PT-2020-1313 · Microsoft · Update Notification Manager+1

Zhiniang Peng

·

Published

2020-01-14

·

Updated

2025-04-08

·

CVE-2020-0638

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Update Notification Manager (affected versions not specified)
Description An elevation of privilege issue exists in the way the Update Notification Manager handles files. To exploit this issue, an attacker would first have to gain execution on the victim system. The vulnerability is related to errors in file processing and can be exploited using a specially crafted application, allowing an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Link Following

Weakness Enumeration

Related Identifiers

BDU:2020-00213
CVE-2020-0638

Affected Products

Update Notification Manager
Windows