CVE-2019-1069 PUBLISHED KEV CVSS 7.800000190734863 HIGH

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.

EPSS 30.46% · 96.7th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
30.46%
96.7th percentile

Affected Products

VendorProductVersions
microsoftwindows_server_190310.0.0
microsoftwindows_10_1803
MicrosoftWindows 10 Version 180310.0.0
microsoftwindows_server_180310.0.0
microsoftwindows_server_201610.0.14393.0, 10.0.14393.0
microsoftwindows_10_180910.0.0, 10.0.17763.0, 10.0.0
MicrosoftWindows 10 Version 150710.0.10240.0
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0
microsoftwindows_101709, 1607, 1703
MicrosoftWindows 10 Version 1903 for ARM64-based Systems10.0.0
microsoftwindows_10_1903
MicrosoftWindows 10 Version 1903 for 32-bit Systems10.0.0
microsoftwindows_server_201910.0.17763.0, 10.0.17763.0
MicrosoftWindows Server, version 1803 (Server Core Installation)10.0.0
MicrosoftWindows Server 201610.0.14393.0
microsoftwindows_10_1703
MicrosoftWindows 10 Version 180910.0.17763.0, 10.0.0
microsoftwindows_1010.0.0, 10.0.0, 10.0.0
MicrosoftWindows 10 Version 1709 for 32-bit Systems10.0.0
MicrosoftWindows Server 201910.0.17763.0

…and 11 more

Timeline

References

Open in Interactive Console →