January 28, 2022 · Applied Cybernetics Group
CVE-2020-0787 — Microsoft Windows
known ransomware use
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
- Added to KEV
2022-01-28- Federal due date
2022-07-28- Vendor
- Microsoft
- Product
- Windows
- EPSS
- 98.6th percentile (score 0.425, as of
2026-09-16) - NVD CVSS v3.1
- 7.8 (HIGH)
- Ransomware use
- Known
- ATT&CK
- T1059 , T1068 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-0787
CISA short description
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
Required action
Apply updates per vendor instructions.
NVD description
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.