7.8
CVE-2020-0638
- EPSS 3.04%
- Veröffentlicht 14.01.2020 23:15:32
- Zuletzt bearbeitet 12.08.2026 05:17:27
- Erkennungen
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1709 Version - HwPlatform arm64
Microsoft ≫ Windows 10 1709 Version - HwPlatform x64
Microsoft ≫ Windows 10 1803 Version - HwPlatform arm64
Microsoft ≫ Windows 10 1803 Version - HwPlatform x64
Microsoft ≫ Windows 10 1809 Version - HwPlatform arm64
Microsoft ≫ Windows 10 1809 Version - HwPlatform x64
Microsoft ≫ Windows 10 1809 Version - HwPlatform x86
Microsoft ≫ Windows 10 1903 Version - HwPlatform arm64
Microsoft ≫ Windows 10 1903 Version - HwPlatform x64
Microsoft ≫ Windows 10 1903 Version - HwPlatform x86
Microsoft ≫ Windows 10 1909 Version - HwPlatform arm64
Microsoft ≫ Windows 10 1909 Version - HwPlatform x64
Microsoft ≫ Windows 10 1909 Version - HwPlatform x86
Microsoft ≫ Windows Server 1803 Version -
Microsoft ≫ Windows Server 1903 Version -
Microsoft ≫ Windows Server 1909 Version -
Microsoft ≫ Windows Server 2019 Version -
23.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Update Notification Manager Privilege Escalation Vulnerability
SchwachstelleMicrosoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.04% | 0.86 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0638
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0638