CVE-2020-1313 is an elevation of privilege vulnerability in the Windows Update Orchestrator Service. The vulnerability arises due to improper handling of file operations by the service, which could allow a local attacker to gain elevated privileges on the system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2020-1313, a local privilege escalation vulnerability in Microsoft Windows 10 (builds 1903-2004). The exploit abuses the UniversalOrchestrator ScheduleWork API, which fails to verify the caller's token, allowing a low-privileged user to schedule a job to be executed as SYSTEM. The module uploads both an exploit binary and a customizable payload (typically a Meterpreter or other shell), writes them to a writable directory (default %TEMP%), and schedules the payload for execution as SYSTEM. The exploit checks and interacts with the registry key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler' to confirm job scheduling. The module is operational, requiring a Meterpreter session on a vulnerable system, and provides privilege escalation to SYSTEM. Artifacts are left on disk and in logs, and manual cleanup of the payload is required.
This repository is a proof-of-concept (PoC) exploit for CVE-2020-1313, a local privilege escalation vulnerability in the Windows Update Orchestrator (UniversalOrchestrator) service on Windows 10 and Windows Server Core. The vulnerability allows any local user to schedule a command to be executed as SYSTEM via a DCOM interface, due to improper authorization checks. The exploit is implemented in C++ and consists of a Visual Studio project with a single main code file (UniversalOrchestratorPrivEscPoc.cpp). The PoC connects to the vulnerable COM interface, schedules the execution of 'cmd.exe' with arguments to write the output of 'whoami' and 'whoami /priv' to 'c:\x.txt', and informs the user that the command will be executed by the system service (typically overnight or after a 3-day SLA). The exploit demonstrates the ability to escalate privileges from any user to SYSTEM. The repository also documents the registry key where scheduled work is recorded. No network or remote attack vector is present; exploitation requires local access.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.