Starting in October, still-supported versions of Windows with the exception of Vista, will be offered only cumulative packages.

An attacker who successfully exploited this vulnerability could elevate their permissions from unprivileged user account to administrator. The vulnerability could allow security feature bypass if a physically-present attacker installs an affected boot policy. Offering the security-only update allows enterprises to gradually adopt the monthly rollup, or completely avoid if it they choose. These CU are improving the overall quality of the OS while also significantly reducing the rate of support calls.

