CVE-2020-0638
Summary
| CVE | CVE-2020-0638 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-14 23:15:32 UTC |
| Updated | 2026-08-12 05:17:27 UTC |
| Description | An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.030420000 probability, percentile 0.863280000 (date 2026-08-13)
CISA KEV: Listed on 2022-05-23; due 2022-06-13; ransomware use Known
Problem Types: NVD-CWE-noinfo | CWE-59 | Elevation of Privilege | CWE-59 CWE-59 Improper Link Resolution Before File Access ('Link Following')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 4.6 | AV:L/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
CISA Known Exploited Vulnerability
| Vendor | Microsoft |
|---|---|
| Product | Update Notification Manager |
| Name | Microsoft Update Notification Manager Privilege Escalation Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2020-0638 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows 10 1709 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1709 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1803 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1803 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1809 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1809 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1809 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1903 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1903 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1903 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1909 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1909 | - | All | All | All |
| Operating System | Microsoft | Windows 10 1909 | - | All | All | All |
| Operating System | Microsoft | Windows Server 1803 | - | All | All | All |
| Operating System | Microsoft | Windows Server 1903 | - | All | All | All |
| Operating System | Microsoft | Windows Server 1909 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2019 | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Microsoft | Windows | affected 10 Version 1709 for 32-bit Systems | Not specified |
| CNA | Microsoft | Windows | affected 10 Version 1803 for 32-bit Systems | Not specified |
| CNA | Microsoft | Windows | affected 10 Version 1809 for ARM64-based Systems | Not specified |
| CNA | Microsoft | Windows | affected 10 Version 1803 for x64-based Systems | Not specified |
| CNA | Microsoft | Windows | affected 10 Version 1709 for ARM64-based Systems | Not specified |
| CNA | Microsoft | Windows | affected 10 Version 1709 for x64-based Systems | Not specified |
| CNA | Microsoft | Windows | affected 10 Version 1803 for ARM64-based Systems | Not specified |
| CNA | Microsoft | Windows | affected 10 Version 1809 for 32-bit Systems | Not specified |
| CNA | Microsoft | Windows | affected 10 Version 1809 for x64-based Systems | Not specified |
| CNA | Microsoft | Windows 10 Version 1903 For ARM64-based Systems | affected unspecified | Not specified |
| CNA | Microsoft | Windows 10 Version 1903 For 32-bit Systems | affected unspecified | Not specified |
| CNA | Microsoft | Windows 10 Version 1903 For X64-based Systems | affected unspecified | Not specified |
| CNA | Microsoft | Windows Server | affected 2019 | Not specified |
| CNA | Microsoft | Windows Server | affected 2019 (Core installation) | Not specified |
| CNA | Microsoft | Windows Server | affected version 1803 (Core Installation) | Not specified |
| CNA | Microsoft | Windows Server Version 1903 Server Core Installation | affected unspecified | Not specified |
| CNA | Microsoft | Windows 10 Version 1909 For 32-bit Systems | affected unspecified | Not specified |
| CNA | Microsoft | Windows 10 Version 1909 For X64-based Systems | affected unspecified | Not specified |
| CNA | Microsoft | Windows Server Version 1909 Server Core Installation | affected unspecified | Not specified |
| CNA | Microsoft | Windows 10 Version 1909 For ARM64-based Systems | affected unspecified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0638 | af854a3a-2127-422b-91ae-364da2661108 | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-05-23T00:00:00.000Z | CVE-2020-0638 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.