Executive brief
A privilege escalation vulnerability in the Microsoft Task Scheduler Service occurs when the service fails to properly validate certain file operations. An attacker with unprivileged code execution can exploit this flaw to gain elevated system privileges.
Affected products
- Microsoft Windows 10 1607, 1703, 1709, 1803, 1809, 1903
- Microsoft Windows Server 2016
Timeline
- 2019-06-11: disclosed: Initial disclosure and patch release by Microsoft.
- 2019-06-11: patched: Microsoft released security updates to address the vulnerability.
- 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- exploited: Confirmed as exploited in the wild per CISA KEV catalog.