EXPOSURES › CVE-2019-1069
CVE-2019-1069
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft's Task Scheduler had a privilege escalation vulnerability actively exploited by ransomware actors, allowing attackers to gain elevated system access.
A flaw in Microsoft Task Scheduler's file operation validation allowed privilege escalation, actively exploited in ransomware attacks. DIB organizations using vulnerable systems face potential data breaches and compliance failures (NIST 800-171 controls 3.1.1, 3.1.2, 3.1.3). Patch systems promptly and review task scheduler configurations.
Shame score — The vulnerability's exploitation by ransomware demonstrates a significant security oversight and potential for widespread compromise, despite Microsoft's position as a trusted vendor.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |