Upon successful exploitation, an attacker can delete or edit any Windows file, including system executables, which otherwise only a privileged user can do.
Dubbed AngryPolarBearBug2 by the hacker, the vulnerability is a successor to a previous Windows Error Reporting service vulnerability she found late last year, which was named AngryPolarBearBug and allowed a local, unprivileged attacker to overwrite any chosen file on the system.
https://thehackernews.com/2019/05/microsoft-zero-day-vulnerability.html
https://mobile.twitter.com/TheHackersNews/status/1131567152522178560