ZeroHour

CVE-2020-0787

KEV ransomware PoC mass

Privilege Escalation in Microsoft Windows Background Intelligent Transfer Service (BITS)

CISA: Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability

CVSS 3.1
7.8 high
EPSS
43%p99
Published
()
KEV added
AI analysis

CVE-2020-0787 is a privilege elevation flaw in the Windows Background Intelligent Transfer Service (BITS), which improperly handles symbolic links (CWE-269, CWE-59). An attacker who can already run low-privileged code on a machine — via a phishing payload or a chained remote-code-execution bug — can plant or manipulate symbolic links that BITS follows, causing the service to execute arbitrary code with SYSTEM-level privileges. Successful exploitation grants full control of the host, making this a common link in attack chains, and CISA notes known ransomware use. Because BITS ships by default with Windows, essentially every Windows client and server installation predating the vendor patch is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-28, and EPSS assigns a 42.5% probability of exploitation within 30 days (99th percentile).

What to do: Apply Microsoft's updates for CVE-2020-0787 per vendor instructions (the flaw was addressed in Microsoft's March 2020 security updates) across all Windows clients and servers, prioritizing user workstations and internet-facing systems given known ransomware use. Since this is a local privilege escalation, pair patching with controls that block the initial foothold (MFA, email/phishing defenses, EDR). Verify remediation by confirming endpoints report the relevant update installed and no BITS symlink abuse indicators remain.

Affected
Microsoft Windows
Estimated exposure
massorder of 1 billion+ Windows installations (unpatched systems at risk; patched systems unaffected) — BITS is installed by default on effectively all Windows client and server editions and public estimates put the global Windows installed base at well over a billion devices, so potential exposure is the entire Windows fleet minus hosts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news