CVE-2020-0787
KEV ransomware PoC massPrivilege Escalation in Microsoft Windows Background Intelligent Transfer Service (BITS)
CISA: Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
CVE-2020-0787 is a privilege elevation flaw in the Windows Background Intelligent Transfer Service (BITS), which improperly handles symbolic links (CWE-269, CWE-59). An attacker who can already run low-privileged code on a machine — via a phishing payload or a chained remote-code-execution bug — can plant or manipulate symbolic links that BITS follows, causing the service to execute arbitrary code with SYSTEM-level privileges. Successful exploitation grants full control of the host, making this a common link in attack chains, and CISA notes known ransomware use. Because BITS ships by default with Windows, essentially every Windows client and server installation predating the vendor patch is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-28, and EPSS assigns a 42.5% probability of exploitation within 30 days (99th percentile).
What to do: Apply Microsoft's updates for CVE-2020-0787 per vendor instructions (the flaw was addressed in Microsoft's March 2020 security updates) across all Windows clients and servers, prioritizing user workstations and internet-facing systems given known ransomware use. Since this is a local privilege escalation, pair patching with controls that block the initial foothold (MFA, email/phishing defenses, EDR). Verify remediation by confirming endpoints report the relevant update installed and no BITS symlink abuse indicators remain.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H