---
id: CVE-2020-1112
title: >-
  An elevation of privilege vulnerability exists when the Windows Background
  Intelligent Transfer Service (BITS) IIS module improperly handles uploaded
  content
summary: >-
  An elevation of privilege vulnerability exists when the Windows Background
  Intelligent Transfer Service (BITS) IIS module improperly handles uploaded
  content. An attacker who successfully exploited this vulnerability could
  upload restric…
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: microsoft
product: windows_10
affected:
  - windows_10
  - windows_10 = 1607
  - windows_10 = 1709
  - windows_10 = 1803
  - windows_10 = 1809
  - windows_10 = 1903
  - windows_10 = 1909
  - windows_7
  - windows_8.1
  - windows_rt_8.1
  - windows_server_2008
  - windows_server_2008 = r2
  - windows_server_2012
  - windows_server_2012 = r2
  - windows_server_2016
  - windows_server_2019
published: '2020-05-21'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-1112'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1112'
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1112
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.03266
epssPercentile: 0.87893
ingestedAt: '2026-08-19T17:42:38.396Z'
---

## Overview

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restricted file types to an IIS-hosted folder.
To exploit this vulnerability, an attacker would require permissions to upload files via BITS. An attacker could then submit a specially crafted request to upload a file.
The security update addresses the vulnerability by correcting how Windows BITS validates file names.

## Affected

- `windows_10`
- `windows_10 = 1607`
- `windows_10 = 1709`
- `windows_10 = 1803`
- `windows_10 = 1809`
- `windows_10 = 1903`
- `windows_10 = 1909`
- `windows_7`
- `windows_8.1`
- `windows_rt_8.1`
- `windows_server_2008`
- `windows_server_2008 = r2`
- `windows_server_2012`
- `windows_server_2012 = r2`
- `windows_server_2016`
- `windows_server_2019`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
