PT-2024-7873 · Microsoft+1 · Windows Task Scheduler+7
Bahare Sabouri
+1
·
Published
2024-11-12
·
Updated
2026-04-22
·
CVE-2024-49039
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Task Scheduler versions prior to the fixed version in November Patch Tuesday
Description
The vulnerability is an elevation-of-privilege issue in the Windows Task Scheduler, allowing attackers to elevate their privileges to Medium Integrity level and gain the ability to execute RPC functions restricted to privileged accounts. This vulnerability has been exploited in the wild, with the RomCom group executing malicious code outside the Firefox sandbox and launching malware from C&C servers. The attack can be performed from an AppContainer restricted environment.
Recommendations
To resolve the issue, apply the patch released in November Patch Tuesday for Windows Task Scheduler.
As a temporary workaround, consider restricting access to the Task Scheduler until a patch is applied.
Avoid using the Task Scheduler to execute RPC functions that are restricted to privileged accounts until the issue is resolved.
Apply the latest security updates to prevent exploitation of this vulnerability.
Exploit
Fix
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Windows
Windows 10 1507
Windows 10 1607
Windows 10 1809
Windows 10 21H2
Windows 10 22H2
Windows Task Scheduler