Microsoft has released a new version of the Windows 10 Update Assistant in order to fix a local privilege escalation vulnerability. While there is no imminent threat, the only way to fix this vulnerability is to uninstall the program or download the latest version. The vulnerability could allow an attacker to run a program with SYSTEM privileges, which essentially lets them perform any action they want in Windows. The most realistic use case would be for an APT actor who has persistent and long term access to a machine, according to security researcher Jimmy Bayne.
Source: https://www.bleepingcomputer.com/news/microsoft/windows-10-update-assistant-vulnerability-needs-manual-fix-heres-how/

