Junglewise Threat Intelligence

CVE-2019-1069: Microsoft Task Scheduler Privilege Escalation Vulnerability

CVE-2019-1069 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-15

Technologies: Microsoft Windows Server 2016, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A privilege escalation vulnerability in the Microsoft Task Scheduler Service occurs when the service fails to properly validate certain file operations. An attacker with unprivileged code execution can exploit this flaw to gain elevated system privileges.

Affected products

  • Microsoft Windows 10 1607, 1703, 1709, 1803, 1809, 1903
  • Microsoft Windows Server 2016

Timeline

  • 2019-06-11: disclosed: Initial disclosure and patch release by Microsoft.
  • 2019-06-11: patched: Microsoft released security updates to address the vulnerability.
  • 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • exploited: Confirmed as exploited in the wild per CISA KEV catalog.