PT-2024-7873 · Microsoft+1 · Windows Task Scheduler+7

Bahare Sabouri

+1

·

Published

2024-11-12

·

Updated

2026-04-22

·

CVE-2024-49039

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Task Scheduler versions prior to the fixed version in November Patch Tuesday
Description The vulnerability is an elevation-of-privilege issue in the Windows Task Scheduler, allowing attackers to elevate their privileges to Medium Integrity level and gain the ability to execute RPC functions restricted to privileged accounts. This vulnerability has been exploited in the wild, with the RomCom group executing malicious code outside the Firefox sandbox and launching malware from C&C servers. The attack can be performed from an AppContainer restricted environment.
Recommendations To resolve the issue, apply the patch released in November Patch Tuesday for Windows Task Scheduler. As a temporary workaround, consider restricting access to the Task Scheduler until a patch is applied. Avoid using the Task Scheduler to execute RPC functions that are restricted to privileged accounts until the issue is resolved. Apply the latest security updates to prevent exploitation of this vulnerability.

Exploit

Fix

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-09376
CVE-2024-49039

Affected Products

Firefox
Windows
Windows 10 1507
Windows 10 1607
Windows 10 1809
Windows 10 21H2
Windows 10 22H2
Windows Task Scheduler