CVE Vulnerabilities

CVE-2020-0638

Published: Jan 14, 2020 | Modified: Oct 29, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka Update Notification Manager Elevation of Privilege Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Windows_10_1709Microsoft- (including)- (including)
Windows_10_1803Microsoft- (including)- (including)
Windows_10_1809Microsoft- (including)- (including)
Windows_10_1903Microsoft- (including)- (including)
Windows_10_1909Microsoft- (including)- (including)
Windows_server_1803Microsoft- (including)- (including)
Windows_server_1903Microsoft- (including)- (including)
Windows_server_1909Microsoft- (including)- (including)
Windows_server_2019Microsoft- (including)- (including)

References