LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1069: Microsoft Task Scheduler Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 15, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1069 to its Known Exploited Vulnerabilities catalog on Mar 15, 2022, with a federal patch deadline of Apr 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.

CVE-2019-1069 is a privilege escalation vulnerability in Microsoft Task Scheduler. It allows an attacker who already has some access on a Windows system to gain higher privileges by abusing how the Task Scheduler Service handles certain file operations. Because privilege escalation is a common step in ransomware and other post-compromise activity, this issue matters to any organization running Windows systems that use the built-in task scheduler.

CISA notes that the flaw has been used in ransomware campaigns. Defenders should treat it as a priority for inventory, patching, and monitoring until systems are confirmed remediated per the vendor advisory.

How it works

The weakness is classified as CWE-59, which covers improper link resolution before file access (commonly called link following). In this case, the Task Scheduler Service does not adequately validate certain file operations. An attacker who can influence file paths or links that the service processes may cause it to act on unintended files or locations with the elevated rights of the service.

At a high level, the abuse path is local privilege escalation: the attacker starts with lower-privileged code execution or access and leverages the flawed validation to obtain higher privileges on the same host. Exact exploitation mechanics, preconditions, and affected builds are not detailed here; confirm those specifics directly against the Microsoft advisory for CVE-2019-1069. No remote unauthenticated exploit path is implied by the given description—this is a privilege-escalation issue in the Task Scheduler component.

Am I affected? How to find it in your systems

Microsoft Task Scheduler is a core Windows component present on client and server editions. It is commonly used for scheduled maintenance, application tasks, and administrative automation, so exposure is widespread on unpatched systems.

How to remediate

Apply the Microsoft security update that addresses CVE-2019-1069 as instructed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions. Prioritize internet-facing or high-value systems and any hosts already showing signs of compromise or unusual task activity.

If you can't patch immediately

Compensating controls reduce but do not eliminate risk. Use them only as a bridge until the vendor update is applied.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used after initial access to deploy ransomware or move laterally, which can lead to data theft or encryption. If you have reason to believe a system was compromised before patching, follow your incident-response process: isolate the host, preserve evidence, and hunt for persistence and further attacker activity. As one additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Task Scheduler
WeaknessCWE-59
Added to CISA KEVMar 15, 2022
Federal patch deadlineApr 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities