Skip to content
COOEY

EXPOSURES › CVE-2019-1069

CVE-2019-1069

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-1069 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatchedprivilege-escalation

Microsoft's Task Scheduler had a privilege escalation vulnerability actively exploited by ransomware actors, allowing attackers to gain elevated system access.

A flaw in Microsoft Task Scheduler's file operation validation allowed privilege escalation, actively exploited in ransomware attacks. DIB organizations using vulnerable systems face potential data breaches and compliance failures (NIST 800-171 controls 3.1.1, 3.1.2, 3.1.3). Patch systems promptly and review task scheduler configurations.

Shame score — The vulnerability's exploitation by ransomware demonstrates a significant security oversight and potential for widespread compromise, despite Microsoft's position as a trusted vendor.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized