KEVIntel
7.8
CVSS
High

CVE-2020-0787

PUBLISHED

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links,...

Exploited in the wild Used in malware Low complexity
Vendor
Microsoft
Product
Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)
Published
Mar 12, 2020
EPSS

Description

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

windows cisa malware ransomware metasploit microsoft

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2.0 7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-01-28 00:00:00 UTC · Source

Used in malware

Recorded 2022-01-28 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 28, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

cve_2020_0787_bits_arbitrary_file_move

metasploit · Created Unknown

Metasploit module for CVE-2020-0787

yanghaoi/CVE-2020-0787

github · Created 2021-11-16 11:04:42 UTC · 31 stars

CVE-2020-0787的简单回显

MasterSploit/CVE-2020-0787

github · Created 2020-12-11 09:27:34 UTC · 0 stars

cbwang505/CVE-2020-0787-EXP-ALL-WINDOWS-VERSION

github · Created 2020-06-16 08:57:51 UTC · 715 stars

Support ALL Windows Version

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit