cbcvebase.
CVE-2020-0787
published 2020-03-12

CVE-2020-0787: An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows…

PriorityP185high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-07-28
Exploited in the wild
EPSS
42.52%
98.6th percentile
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10_version_1903_for_32-bit_systems
microsoftwindows_10_version_1903_for_arm64-based_systems
microsoftwindows_10_version_1903_for_x64-based_systems
microsoftwindows_10_version_1909_for_32-bit_systems
microsoftwindows_10_version_1909_for_arm64-based_systems
microsoftwindows_10_version_1909_for_x64-based_systems
microsoftwindows_server

Detection & IOCsextracted from sources · hover to see the quote

pathC:\Windows\System32\WindowsCoreDeviceInfo.dll
  • CVE-2020-0787 exploitation involves BITS improperly handling symbolic links/junctions to perform an arbitrary file move, ultimately overwriting C:\Windows\System32\WindowsCoreDeviceInfo.dll with a malicious DLL, then triggering the Update Session Orchestrator service to execute it as SYSTEM.
  • Monitor for junction creation by medium-integrity (unprivileged) processes targeting privileged directories such as C:\Windows or its subdirectories, which is the core exploitation primitive for CVE-2020-0787 and similar BITS/file-system redirection attacks.
  • Alert on unexpected writes to WindowsCoreDeviceInfo.dll followed by the Update Session Orchestrator service starting, as this sequence indicates active CVE-2020-0787 exploitation for SYSTEM-level DLL hijacking.
  • CVE-2020-0787 has been observed in LockBit 2.0 ransomware intrusions as a privilege escalation technique; correlate BITS symbolic link abuse with ransomware TTPs such as wevtutil log clearing and PsExec lateral movement.
  • ·The Metasploit module exploit/windows/local/cve_2020_0787_bits_arbitrary_file_move only works on Windows 10 and Windows Server 2016 and later, as the Update Session Orchestrator Service (required for the DLL hijack payload execution) was only introduced in Windows 10.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.