---
id: CVE-2020-0638
title: >-
  An elevation of privilege vulnerability exists in the way the Update
  Notification Manager handles files.To exploit this vulnerability, an attacker
  would first have to gain execution on the victim system, aka 'Update
  Notification Manager …
summary: >-
  An elevation of privilege vulnerability exists in the way the Update
  Notification Manager handles files.To exploit this vulnerability, an attacker
  would first have to gain execution on the victim system, aka 'Update
  Notification Manager …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-59
vendor: microsoft
product: windows_10_1709
affected:
  - windows_10_1709
  - windows_10_1803
  - windows_10_1809
  - windows_10_1903
  - windows_10_1909
  - windows_server_1803
  - windows_server_1903
  - windows_server_1909
  - windows_server_2019
published: '2020-01-14'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-0638'
references:
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0638
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0638
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0638
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.02351
epssPercentile: 0.82957
kev: true
kevDateAdded: '2022-05-23'
kevDueDate: '2022-06-13'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-12T05:52:07.436Z'
---

## Overview

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.

## Affected

- `windows_10_1709`
- `windows_10_1803`
- `windows_10_1809`
- `windows_10_1903`
- `windows_10_1909`
- `windows_server_1803`
- `windows_server_1903`
- `windows_server_1909`
- `windows_server_2019`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
