Microsoft fixes elevation of privileges security vulnerability in Windows Setup
Unbeknownst to Windows 10 users until now, a security vulnerability existed in Windows Setup, the process with runs when installing Feature Updates for the operating system.
The vulnerability (CVE-2020-16908) made it possible for a locally authenticated attacker to run arbitrary code with elevated system privileges. This flaw could be exploited to install software, create new user accounts, or interfere with data.
- KB4579311 cumulative update is causing numerous problems for Windows 10 users
- Microsoft is foisting Office web apps on Edge users
- Microsoft is now blocking some third-party drivers in Windows 8.1, 10 and Server
The vulnerability was found in the way Windows Setup handles directories, and Microsoft says that it affects version 1803, 1809, 1903, 1909 and 2004 of Windows 10. The company assures users that systems are only vulnerable to attack during the process of upgrading to a new Feature Update, and at no other time. Now that Feature Update bundles have been refreshed with the patched Setup binaries, however, the vulnerability "no longer exists".
Announcing some details of the security flaw now that it has been fixed, Microsoft explains:
This vulnerability only exists in Windows 10 Setup, which runs temporarily any time a customer upgrades from a previous version of Windows 10 to a newer version (for example, from Windows 10 Version 1909 to Windows 10 Version 2004). A device is vulnerable only while upgrading to a newer version of Windows. At any other time, the device is not vulnerable.
Offering advice to anyone using a management tool to update Windows, the company also says:
If you are using WSUS or MEM ConfigMgr or another third-party management tool, please sync the latest feature update bundles and approve those for deployment. If you are using Windows media, as applicable to your system, please download the latest refreshed media from VLSC or Visual Studio Subscriptions (formerly MSDN), or download the latest applicable Setup Dynamic Update (DU) package and patch your existing media.
You can download the latest Setup DU packages from the Microsoft Update Catalog website. Please follow the instructions in the following article to learn about how to apply a Setup DU package to your existing media. Update remaining media files.
The latest Setup DU Packages can be found here:
- 4582759 -- Windows 10 Version 1803
- 4582760 -- Windows 10 Version 1809
- 4579919 -- Windows 10 Version 1903
- 4579919 -- Windows 10 Version 1909
- 4579308 -- Windows 10 Version 2004