netVigilance Vulnerability intelligence since 2004
CVE-2020-0787 · netVigilance record NV22-0037

Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management

past due ransomware

What to do

Apply updates per vendor instructions.

CISA deadline 2022-07-28 · passed 4 years 1 month ago · applies to US federal civilian agencies; used elsewhere as a reference SLA

What happened

Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.

Who is affected

Microsoft Windows. Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.

Weakness class: CWE-269, CWE-59.

Timeline

  1. Added to CISA KEVExploitation in the wild confirmed by CISA
  2. CISA remediation deadlinepassed 4 years 1 month ago

Sources