There are two ways to fix the Windows 10 Update Assistant vulnerability: automatically and manually. They are likely found in Settings > Apps & Features. To check if it is installed, you can check to see if the KB4023814 update is installed or search for any files on your device labeled Windows10Upgrade.
It can be installed manually by the user or it can be installed as part of the KB4023814 update. Windows 10 Update Assistant is not a standalone program and will install itself into Windows. While most experts in the field agree that it is ideal to run the patch to have the most updated version of a software, the majority agree that the potential exposure to harm from this particular issue is small enough that it is acceptable to wait for the next round of updates to fix it automatically. The small matter of a restart is often enough for many people to postpone or avoid updates entirely. Updates are often inconvenient even through the easiest of methods. However, Baynes still recommends users to always run the latest version of the software available, especially when older versions have known vulnerabilities. Jimmy Baynes, the security researcher that discovered the vulnerability, thinks that the issue is not a major concern and can only be exploited under specific circumstances. To address the vulnerability, Microsoft released an updated Windows 10 Update Assistant. The Windows 10 Update Assistant contained a local escalation vulnerability that could allow an attacker to run programs with system privileges. In October 2019, Microsoft released a patch to address security fixes and posted a bulletin for a local privilege escalation vulnerability. Users running Windows 10 may need to perform an upgrade to Windows 10 Update Assistant manually if the problem is not automatically corrected. Microsoft discovered that the assistant program itself, not an update for Windows, contains a vulnerability that needs an upgrade to address. The update assistant helps users automatically follow and check for any upgrade available for Windows 10. Windows Update Assistant is a Microsoft program that automatically helps to download and install the latest update and upgrade for Windows.
Microsoft was quick to recognize this vulnerability and released guidelines on how to address the potential problem.
While updates sometimes cause problems with a user's Windows device, in this case, it is the Update Assistant itself that is the source of vulnerability. Windows users might need to manually update the program to address the potential problem.
Microsoft released a new version of Windows 10 Update Assistant in October 2019 to fix a security vulnerability.