CVE-2020-0728 is an information disclosure vulnerability in the Windows Modules Installer Service. The vulnerability arises from improper disclosure of file information by the service, potentially allowing a local attacker to obtain sensitive file information that should not be accessible under normal circumstances.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2020-0728, a local privilege escalation vulnerability in Microsoft Windows. The vulnerability exists in the TrustedInstaller service's handling of the Sxs Store COM class (CLSID 3C6859CE-230B-48A4-BE6C-932C0C202048), which allows any local user to interact with the ISxsStore interface due to overly permissive access controls. The exploit leverages this to bypass file system access controls and read arbitrary files as SYSTEM by abusing the installation process and junction points. The main exploit is implemented in 'sxscopy/sxscopy.cpp', which builds an executable ('sxscopy.exe') that takes a source file and a destination file as arguments. It creates a junction and a crafted manifest to trick the Sxs Store service into copying the target file (even if access is denied to the user) into the WinSXS directory, from which it is then copied to the user-specified destination. The exploit requires a valid '.cat' file and uses Windows command-line utilities to set up the environment. A secondary tool, 'sxsrunmf/sxsrunmf.cpp', appears to be for running arbitrary manifests through the same COM interface, possibly for further experimentation or research into the Sxs Store's behavior. The exploit is local-only and does not provide remote code execution. It is a PoC and does not include weaponized features such as automated privilege escalation or persistence. The code is written in C++ and is intended for researchers or red teamers to demonstrate the vulnerability and its impact.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.