Executive brief
An elevation of privilege vulnerability exists in the Microsoft Update Notification Manager due to improper handling of files. An attacker who has already gained execution on a victim system could exploit this to elevate their privileges.
Affected products
- Microsoft Windows 10 1709, 1803, 1809, 1903, 1909
- Microsoft Windows Server 2016 1803, 1903, 1909
- Microsoft Windows Server 2019 -
- Microsoft Windows Server 1803, 1903, 1909
Timeline
- 2020-01-14: disclosed: NVD Published Date
- 2020-01-14: patched: Microsoft advisory and patch released
- 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-23: exploited: Reported as exploited in the wild per CISA KEV entry