Task Scheduler Elevation of Privilege Vulnerability
Published Jun 12, 2019 ·Due Apr 5, 2022
7.8
HIGHCVSS 3.1
EPSS 6.12%
Description
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.
Affected products
-
- Version 10.0.10240.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.14393.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version 10.0.17763.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.14393.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.14393.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.17763.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.17763.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Windows 10 Version 1507 | n/a |
| |||||||||
| Microsoft | Windows 10 Version 1607 | n/a |
| |||||||||
| Microsoft | Windows 10 Version 1703 | n/a |
| |||||||||
| Microsoft | Windows 10 Version 1709 | n/a |
| |||||||||
| Microsoft | Windows 10 Version 1709 for 32-bit Systems | n/a |
| |||||||||
| Microsoft | Windows 10 Version 1803 | n/a |
| |||||||||
| Microsoft | Windows 10 Version 1809 | n/a |
| |||||||||
| Microsoft | Windows 10 Version 1903 for 32-bit Systems | n/a |
| |||||||||
| Microsoft | Windows 10 Version 1903 for ARM64-based Systems | n/a |
| |||||||||
| Microsoft | Windows 10 Version 1903 for x64-based Systems | n/a |
| |||||||||
| Microsoft | Windows Server 2016 | n/a |
| |||||||||
| Microsoft | Windows Server 2016 (Server Core installation) | n/a |
| |||||||||
| Microsoft | Windows Server 2019 | n/a |
| |||||||||
| Microsoft | Windows Server 2019 (Server Core installation) | n/a |
| |||||||||
| Microsoft | Windows Server, version 1803 (Server Core Installation) | n/a |
| |||||||||
| Microsoft | Windows Server, version 1903 (Server Core installation) | n/a |
|
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
-
- Version 1607StatusaffectedConstraints-
- Version 1703StatusaffectedConstraints-
- Version 1709StatusaffectedConstraints-
- Version 1803StatusaffectedConstraints-
- Version
-
- Version 1803StatusaffectedConstraints-
- Version 1903StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Windows 10 | n/a |
| |||||||||||||||
| Microsoft | Windows Server 2016 | n/a |
| |||||||||||||||
| Microsoft | Windows Server 2019 | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
Mar 15, 2022
Patch Due
Apr 5, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Sep 18, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (44 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.12% (0.06117) | 93.22th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.17% (0.06167) | 92.55th | v5 (v2026.06.15) |
| May 22, 2026 | 32.50% (0.32495) | 96.93th | v4 (v2025.03.14) |
| Nov 22, 2025 | 30.46% (0.30456) | 96.50th | v4 (v2025.03.14) |
| Nov 21, 2025 | 28.68% (0.28675) | 96.33th | v4 (v2025.03.14) |
| Nov 18, 2025 | 24.18% (0.24178) | 95.71th | v4 (v2025.03.14) |
| Nov 16, 2025 | 28.68% (0.28675) | 96.32th | v4 (v2025.03.14) |
| Oct 30, 2025 | 27.21% (0.27207) | 96.16th | v4 (v2025.03.14) |
| Oct 28, 2025 | 35.32% (0.35315) | 96.84th | v4 (v2025.03.14) |
| Oct 22, 2025 | 32.97% (0.32969) | 96.66th | v4 (v2025.03.14) |
| Sep 21, 2025 | 29.84% (0.29837) | 96.50th | v4 (v2025.03.14) |
| Sep 3, 2025 | 32.74% (0.32741) | 96.76th | v4 (v2025.03.14) |
| Jun 15, 2025 | 31.69% (0.31692) | 96.55th | v4 (v2025.03.14) |
| May 22, 2025 | 33.12% (0.33117) | 96.65th | v4 (v2025.03.14) |
| May 21, 2025 | 31.53% (0.31531) | 96.52th | v4 (v2025.03.14) |
| Mar 30, 2025 | 10.37% (0.10373) | 92.47th | v4 (v2025.03.14) |
| Mar 29, 2025 | 4.76% (0.04764) | 82.02th | v4 (v2025.03.14) |
| Mar 28, 2025 | 10.37% (0.10373) | 92.48th | v4 (v2025.03.14) |
| Mar 27, 2025 | 4.76% (0.04764) | 87.98th | v4 (v2025.03.14) |
| Mar 20, 2025 | 10.24% (0.10236) | 92.51th | v4 (v2025.03.14) |
| Mar 19, 2025 | 5.47% (0.05470) | 88.97th | v4 (v2025.03.14) |
| Mar 17, 2025 | 14.20% (0.14200) | 93.86th | v4 (v2025.03.14) |
| Dec 17, 2024 | 4.49% (0.04485) | 92.36th | v3 (v2023.03.01) |
| Dec 12, 2024 | 0.46% (0.00462) | 76.21th | v3 (v2023.03.01) |
| Jun 23, 2024 | 0.42% (0.00417) | 74.22th | v3 (v2023.03.01) |
| Jun 5, 2024 | 0.36% (0.00359) | 71.41th | v3 (v2023.03.01) |
| Apr 17, 2024 | 0.29% (0.00294) | 68.92th | v3 (v2023.03.01) |
| Mar 12, 2024 | 0.28% (0.00283) | 67.93th | v3 (v2023.03.01) |
| Feb 15, 2024 | 0.40% (0.00399) | 72.91th | v3 (v2023.03.01) |
| Feb 7, 2024 | 0.40% (0.00399) | 70.91th | v3 (v2023.03.01) |
| Jan 6, 2024 | 0.39% (0.00387) | 70.38th | v3 (v2023.03.01) |
| Sep 7, 2023 | 0.45% (0.00448) | 71.92th | v3 (v2023.03.01) |
| Jul 22, 2023 | 0.41% (0.00412) | 70.52th | v3 (v2023.03.01) |
| Jun 19, 2023 | 0.35% (0.00351) | 67.84th | v3 (v2023.03.01) |
| Jun 5, 2023 | 0.29% (0.00288) | 64.33th | v3 (v2023.03.01) |
| Apr 16, 2023 | 0.38% (0.00383) | 68.94th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.27% (0.00270) | 62.66th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.69% (0.01690) | 76.10th | v2 (v2022.01.01) |
| May 21, 2022 | 1.69% (0.01690) | 74.32th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.41% (0.01413) | 70.95th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.41% (0.01413) | 50.23th | v2 (v2022.01.01) |
| Feb 3, 2022 | 30.10% (0.30098) | 96.74th | v1 |
| Sep 1, 2021 | 30.10% (0.30098) | 98.51th | v1 |
| Apr 14, 2021 | 30.10% (0.30098) | 0.00th | v1 |
References (5)
- https://blog.0patch.com/2019/06/another-task-scheduler-0day-another.html ExploitThird Party Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1069 vendor-advisoryPatchVendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1069 PatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1069 government-resourceUS Government Resource
- https://www.kb.cert.org/vuls/id/119704 Third Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://blog.0patch.com/2019/06/another-task-scheduler-0day-another.html | ExploitThird Party Advisory | |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1069 | vendor-advisoryPatchVendor Advisory | |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1069 | PatchVendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1069 | government-resourceUS Government Resource | |
| https://www.kb.cert.org/vuls/id/119704 | Third Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.