Executive brief
An elevation of privilege vulnerability exists in the Microsoft Windows Background Intelligent Transfer Service (BITS) due to improper handling of symbolic links. A local attacker can exploit this by following links to execute arbitrary code with SYSTEM-level privileges.
Affected products
- Microsoft Windows 10 1507, 1607, 1709, 1803, 1809, 1903, 1909
- Microsoft Windows 7 Service Pack 1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 1803, 1903, 1909
- Microsoft Windows Server 2019
Timeline
- 2020-03-10: disclosed: Initial publication date based on CVE year and typical Microsoft patch cycles (MSRC)
- 2022-01-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-28: other: NVD publication date