This content originally appeared on DEV Community and was authored by Freedom Coder
CVE ID
CVE-2024-49039
Vulnerability Name
Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
- Project: Microsoft
- Product: Windows
Date
- Date Added: 2024-11-12
- Due Date: 2024-12-03
Description
Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039 ; https://nvd.nist.gov/vuln/detail/CVE-2024-49039
Related Security News
- Details emerge on WinRAR zero-day attacks that infected PCs with malware
- Google Reports 75 Zero-Days Exploited in 2024 — 44% Targeted Enterprise Security Products
- Mozilla warns Windows users of critical Firefox sandbox escape flaw
- Firefox and Windows zero-days exploited by Russian RomCom hackers
- RomCom Exploits Zero-Day Firefox and Windows Flaws in Sophisticated Cyberattacks
- Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler Bugs
More CVEs Info
Common Vulnerabilities & Exposures (CVE) List
This content originally appeared on DEV Community and was authored by Freedom Coder