CVE-2019-1069: Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations, aka 'Task Scheduler Elevation of Privilege Vulnerability'.
Other sources
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.
— Microsoft
Microsoft Windows Task Scheduler contains a privilege escalation vulnerability in the way that the SetJobFileSecurityByName() function is used that can allow an authenticated attacker to gain SYSTEM privileges on an affected system.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4503279 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4503327 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4503286 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4503267 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4503291 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4503293 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4503284
Event History
Frequently Asked Questions
What is CVE-2019-1069?
CVE-2019-1069 is an elevation of privilege vulnerability in the Task Scheduler Service of Microsoft Windows.
What is the severity of CVE-2019-1069?
The severity of CVE-2019-1069 is rated as high.
Which software is affected by CVE-2019-1069?
Microsoft Task Scheduler on Windows 10, Microsoft Windows Server 2016, and Microsoft Windows Server 2019 are affected by CVE-2019-1069.
How does CVE-2019-1069 work?
CVE-2019-1069 exploits a vulnerability in the way the Task Scheduler Service validates certain file operations, allowing an attacker to escalate privileges.
How can I fix CVE-2019-1069?
To fix CVE-2019-1069, install the security updates provided by Microsoft and follow their recommended mitigation steps.