CVE-2019-1378: Microsoft Windows 10 Update Assistant

High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.

An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 Update Assistant Elevation of Privilege Vulnerability'.

Affected products

  • Microsoft Windows 10 Update Assistant: affected versions not specified

Published 2019-10-10. Last modified 2026-06-17.