CVE-2019-1069 is an elevation of privilege vulnerability affecting Microsoft Windows Task Scheduler. An attacker with unprivileged code execution could exploit this flaw by manipulating how the Task Scheduler Service validates file operations, leading to elevated privileges on the system. With a CVSS score of 7.8 (High), the vulnerability is easily exploitable locally with no user interaction required, potentially resulting in full compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, including in known ransomware campaigns, and has garnered significant community discussion and media coverage, despite no public Metasploit or ExploitDB modules being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.