CVE-2020-0787: Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
Other sources
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0787?
The severity of CVE-2020-0787 is rated as important based on its potential to allow an attacker to gain elevated privileges on the affected system.
How do I fix CVE-2020-0787?
CVE-2020-0787 can be mitigated by applying the security updates provided by Microsoft that address the vulnerability.
What versions of Windows are affected by CVE-2020-0787?
CVE-2020-0787 affects multiple versions of Windows including Windows 10, Windows 7, Windows 8.1, and various Windows Server editions.
What is the nature of CVE-2020-0787?
CVE-2020-0787 is an elevation of privilege vulnerability that occurs when the Windows Background Intelligent Transfer Service improperly manages symbolic links.
Can CVE-2020-0787 be exploited remotely?
CVE-2020-0787 requires local access for exploitation, meaning an attacker must have physical or authenticated access to the system.