PoC Index

CVE-2020-0787

KEV RANSOMWAREHIGH 7.8EPSS 42.5%

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
42.52% chance of exploitation in the next 30 days, 99th percentile
CISA KEV
added 2022-01-28, used in ransomware campaigns
Published
2020-03-12
Updated
2026-08-12

Proof-of-concept exploits (3)

Metasploit modules (1)

Exploit collections (1)

References

Related