CVE-2019-1069
Act now ● On CISA KEV — actively exploited used in ransomware
Actively exploited — on the CISA KEV list.
CVSS base
7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
6.1%
93.1th percentile
CISA KEV
Listed
Added 2022-03-15 · patch by 2022-04-05
Weakness / dates
CWE-59
Published 2019-06-12 · modified 2026-08-12
CVSS breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | L | Local |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | H | High |
| Integrity | H | High |
| Availability | H | High |
Timeline
- 2019-06-12 — Published (NVD)
- 2022-03-15 — Added to CISA KEV (actively exploited)
- 2022-04-05 — CISA patch-by deadline
- 2026-08-12 — Last modified (NVD)
Description
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.
Affected
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1069
- exploit https://blog.0patch.com/2019/06/another-task-scheduler-0day-another.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1069
- https://www.kb.cert.org/vuls/id/119704
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1069