All CVEs View on NVD
CVE-2020-0787
HIGH7.8
CISA KEV
Published 2020-03-12 · Updated 2026-08-12 · Source secure@microsoft.com
Description
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-59CWE-59
CISA Known-Exploited Vulnerability
Product: Microsoft — Windows
Name: Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
Date added: 2022-01-28 · Due: 2022-07-28
USED IN RANSOMWARE
Required action: Apply updates per vendor instructions.
References
- http://packetstormsecurity.com/files/158056/Background-Intelligent-Transfer-Service-Privilege-Escalation.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0787
- http://packetstormsecurity.com/files/158056/Background-Intelligent-Transfer-Service-Privilege-Escalation.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0787
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0787

