CVE-2019-1069
Microsoft Task Scheduler Privilege Escalation Vulnerability
CVSS
7.8
High
EPSS
6.1%
p93
KEV
YES
Mar 15, 2022
Exploit Today
78
0-100
Published: Jun 12, 2019 · Last modified: Aug 12, 2026 · CWE-59
Product
Microsoft / Task Scheduler
Vulnerability
Microsoft Task Scheduler Privilege Escalation Vulnerability
Added to KEV
Mar 15, 2022
Remediate by
Apr 5, 2022
Known ransomware use
Yes
Summary description
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2019-1069
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.
- msrc.microsoft.comhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1069
- blog.0patch.comhttps://blog.0patch.com/2019/06/another-task-scheduler-0day-another.html
- portal.msrc.microsoft.comhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1069
- www.kb.cert.orghttps://www.kb.cert.org/vuls/id/119704
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1069