CVE-2020-0787
KEV
🔴 Łataj teraz
Luka w Windows BITS umożliwia eskalację uprawnień przez niewłaściwe zarządzanie linkami symbolicznymi.
CVSS
7.8
EPSS
42.5%
Exploit
weaponized
Vendor
microsoft
Opis źródłowy (NVD)
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
exploit privilege-escalation
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 42.5% |
| Opublikowano (NVD) | 2020-03-12 16:15:15 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-12 05:17:28 UTC |
Referencje
- http://packetstormsecurity.com/files/158056/Background-Intelligent-Transfer-Service-Privilege-Escalation.html (secure@microsoft.com) [Exploit, Third Party Advisory, VDB Entry]
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0787 (secure@microsoft.com) [Patch, Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0787 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]