VDB

CVE-2019-1069

CVE-2019-1069 PUBLISHED KEV CVSS 7.800000190734863 HIGH

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.

EPSS 32.50% · 97.0th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
32.50%
97.0th percentile

Affected Products

VendorProductVersions
microsoftwindows_server_190310.0.0
microsoftwindows_10_1803
MicrosoftWindows 10 Version 180310.0.0
microsoftwindows_server_180310.0.0
microsoftwindows_server_201610.0.14393.0, 10.0.14393.0
microsoftwindows_10_180910.0.17763.0, 10.0.0, 10.0.0
MicrosoftWindows 10 Version 150710.0.10240.0
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0
microsoftwindows_101709, 1607, 1607
MicrosoftWindows 10 Version 1903 for ARM64-based Systems10.0.0
microsoftwindows_10_1903
MicrosoftWindows 10 Version 1903 for 32-bit Systems10.0.0
microsoftwindows_server_201910.0.17763.0, 10.0.17763.0
MicrosoftWindows Server, version 1803 (Server Core Installation)10.0.0
MicrosoftWindows Server 201610.0.14393.0
microsoftwindows_10_1703
MicrosoftWindows 10 Version 180910.0.0, 10.0.17763.0
microsoftwindows_1010.0.0, 10.0.0, 10.0.0
MicrosoftWindows 10 Version 1709 for 32-bit Systems10.0.0
MicrosoftWindows Server 201910.0.17763.0

…and 11 more

Timeline

  • May 23, 2019 PoC Published
  • Jun 12, 2019 CVE Published
  • Oct 9, 2020 PoC Published
  • Jan 10, 2021 PoC Published
  • Apr 14, 2021 EPSS Score
  • Apr 16, 2021 VulnCheck KEV Exploitation
  • Jun 22, 2021 PoC Published
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Mar 15, 2022 CISA KEV Added
  • Mar 24, 2022 VulnCheck KEV Exploitation
Open in Interactive Console →
$ Console Community · 100/wk Open console ›