Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server - CVE-2020-1255
Published: June 9, 2020
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the way Windows Background Intelligent Transfer Service (BITS) IIS module handles uploaded content. A remote authenticated attacker can upload restricted file types to an IIS-hosted folder
To exploit this vulnerability, an attacker would require permissions to upload files via BITS.
Affected software
Windows Server