CVE-2019-1378

HIGH

Windows 10 Update Assistant - Privilege Escalation

Title source: llm
STIX 2.1

Description

An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 Update Assistant Elevation of Privilege Vulnerability'.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 31.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
microsoft/windows_10_update_assistant
Published Oct 10, 2019
Tracked Since Feb 18, 2026