PT-2020-1912 · Microsoft · Windows Background Intelligent Transfer Service+1

Published

2020-03-10

·

Updated

2025-12-20

·

CVE-2020-0787

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Background Intelligent Transfer Service (BITS) versions prior to the fixed version
Description The issue is related to errors in handling symbolic links that display paths to files and directories. This can allow an attacker to elevate their privileges using a specially crafted application. The vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles these links.
Recommendations For Windows Background Intelligent Transfer Service (BITS) versions prior to the fixed version, consider disabling the service until a patch is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Link Following

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-01189
CVE-2020-0787

Affected Products

Windows
Windows Background Intelligent Transfer Service