LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-0638: Microsoft Update Notification Manager Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 23, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 13, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-0638 to its Known Exploited Vulnerabilities catalog on May 23, 2022, with a federal patch deadline of Jun 13, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.

CVE-2020-0638 is a privilege escalation vulnerability in Microsoft Update Notification Manager. An attacker who already has some level of access on a Windows system could abuse it to gain higher privileges. CISA notes that this issue has been used in ransomware activity, which makes timely remediation important for any environment still running the affected component.

Public technical detail is limited beyond the privilege-escalation classification. Confirm exact product versions, patch identifiers, and deployment guidance directly against the Microsoft security advisory before acting.

How it works

The vulnerability resides in Microsoft Update Notification Manager and allows privilege escalation. In general terms, privilege-escalation flaws let a lower-privileged process or user obtain rights belonging to a higher-privileged context, such as SYSTEM or an administrative account. An attacker who has already achieved code execution or a foothold under a limited account can leverage the flaw to expand control over the host.

Because the CWE and low-level mechanics are not specified in the available summary, defenders should treat this as a local elevation-of-privilege issue typical of Windows update-related components. Exact trigger conditions, required permissions, and exploitation steps must be taken only from the vendor advisory; do not rely on unverified public write-ups.

Am I affected? How to find it in your systems

Microsoft Update Notification Manager is part of the Windows update notification stack and is commonly present on client and server editions that receive Windows Update notifications. Inventory efforts should focus on Windows endpoints and servers that have not yet received the corresponding security update.

If your patch-management data cannot confirm the fix, treat the host as potentially vulnerable until verified.

How to remediate

Apply the security update supplied by Microsoft for CVE-2020-0638 as the primary remediation. Follow the vendor’s installation and reboot guidance exactly; CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

When immediate patching is not feasible, reduce the attack surface and increase detection until the update can be applied.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used by ransomware operators to gain the rights needed for encryption, data theft, or further lateral movement. If you have evidence of exploitation or cannot rule out compromise, follow your incident-response plan: isolate affected hosts, preserve forensic data, reset credentials, and assess whether sensitive data left the environment. You can also run a free exposure scan of your email addresses against known breach datasets to check whether associated credentials or personal data have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Update Notification Manager
Added to CISA KEVMay 23, 2022
Federal patch deadlineJun 13, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities