#VU28889 Permissions, Privileges, and Access Controls in Windows and Windows Server - CVE-2020-1255
Published: June 9, 2020
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the way Windows Background Intelligent Transfer Service (BITS) IIS module handles uploaded content. A remote authenticated attacker can upload restricted file types to an IIS-hosted folder
To exploit this vulnerability, an attacker would require permissions to upload files via BITS.