CVE-2020-0754 is an elevation of privilege vulnerability in Windows Error Reporting (WER). The vulnerability exists due to improper handling and execution of files by WER, which could allow a local attacker to execute arbitrary code with elevated privileges. This issue is distinct from CVE-2020-0753 and affects supported versions of Microsoft Windows.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a comprehensive set of proof-of-concept (PoC) exploits and writeups for multiple Windows privilege escalation vulnerabilities, including CVE-2020-0753 and CVE-2020-0754 (Windows Error Reporting service) and six vulnerabilities in Microsoft OneDrive scheduled tasks. The exploits target improper handling of hardlinks, symlinks, and file type checks in privileged processes, allowing a standard user to overwrite or delete arbitrary files with SYSTEM privileges. The repository includes C++ source code for creating hardlinks, symlinks, and setting oplocks, as well as PowerShell and batch scripts to automate the exploitation process. The structure is organized by target (e.g., FileSyncConfig, FileSyncHelper, OneDriveSetup, WER) and includes detailed reports and PoCs for each vulnerability. The main attack vector is local privilege escalation via file system race conditions and link manipulation. The repository demonstrates advanced exploitation techniques such as PID prediction via oplocks and multi-level junction/symlink attacks, and provides all necessary code and scripts to reproduce the vulnerabilities on affected Windows systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.