---
id: CVE-2020-1138
title: >-
  An elevation of privilege vulnerability exists when the Storage Service
  improperly handles file operations
summary: >-
  An elevation of privilege vulnerability exists when the Storage Service
  improperly handles file operations. An attacker who successfully exploited
  this vulnerability could gain elevated privileges on the victim system.

  To exploit the vul…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: microsoft
product: windows_10
affected:
  - windows_10 = 1709
  - windows_10 = 1803
  - windows_10 = 1809
  - windows_10 = 1903
  - windows_10 = 1909
  - windows_server_2016
  - windows_server_2016 = 1803
  - windows_server_2016 = 1903
  - windows_server_2016 = 1909
  - windows_server_2019
published: '2020-05-21'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-1138'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1138'
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1138
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00855
epssPercentile: 0.56613
ingestedAt: '2026-08-19T17:42:39.019Z'
---

## Overview

An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.
To exploit the vulnerability, an attacker would first have to gain execution on the victim system, then run a specially crafted application.
The security update addresses the vulnerability by correcting how the Storage Services handles file operations.

## Affected

- `windows_10 = 1709`
- `windows_10 = 1803`
- `windows_10 = 1809`
- `windows_10 = 1903`
- `windows_10 = 1909`
- `windows_server_2016`
- `windows_server_2016 = 1803`
- `windows_server_2016 = 1903`
- `windows_server_2016 = 1909`
- `windows_server_2019`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
