CVE-2020-0787
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
CVSS
7.8
High
EPSS
42.5%
p99
KEV
YES
Jan 28, 2022
Exploit Today
80
0-100
Published: Mar 12, 2020 · Last modified: Aug 12, 2026 · CWE-59
Product
Microsoft / Windows
Vulnerability
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
Added to KEV
Jan 28, 2022
Remediate by
Jul 28, 2022
Known ransomware use
Yes
Summary description
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2020-0787
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
- packetstormsecurity.comhttp://packetstormsecurity.com/files/158056/Background-Intelligent-Transfer-Service-Privilege-Escalation.html
- portal.msrc.microsoft.comhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0787
- packetstormsecurity.comhttp://packetstormsecurity.com/files/158056/Background-Intelligent-Transfer-Service-Privilege-Escalation.html
- portal.msrc.microsoft.comhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0787
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0787