cbcvebase.
CVE-2019-1069
published 2019-06-12

CVE-2019-1069: An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited…

PriorityP184high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-05
Exploited in the wild
EPSS
6.12%
92.6th percentile
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.

Affected

24 ranges
VendorProductVersion rangeFixed in
microsoftwindows_10_version_1507>= 10.0.10240.0 < publicationpublication
microsoftwindows_10_version_1607>= 10.0.14393.0 < publicationpublication
microsoftwindows_10_version_1703>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1709>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1709_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1803>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.17763.0 < publicationpublication
microsoftwindows_10_version_1903_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_arm64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_x64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_server_2016>= 10.0.14393.0 < publicationpublication
microsoftwindows_server_2019>= 10.0.17763.0 < publicationpublication
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1703
msrcwindows_10_version_1709
msrcwindows_10_version_1803
msrcwindows_10_version_1809
msrcwindows_10_version_1903
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_version_1803
msrcwindows_server_version_1903

Detection & IOCsextracted from sources · hover to see the quote

filenamekiller.bat
filenameYDArk.exe
  • CVE-2019-1069 exploited by TargetCompany ransomware as an initial access / privilege escalation vector alongside CVE-2020-0618; look for Task Scheduler Service abuse by unprivileged processes.
  • Post-exploitation chain involves a PowerShell script downloading a malicious file from a C&C server and executing it via WMIC; monitor for WMIC spawning processes from PowerShell-downloaded payloads.
  • Reflective loading observed: PowerShell script downloads a .NET downloader which retrieves an encrypted payload from C&C, decrypted via XOR or inversion and executed in-memory; monitor for in-memory .NET assembly loading from PowerShell.
  • Attackers manually uninstall AV products using GMER and Advance Process Termination tools; alert on execution of these tools in enterprise environments.
  • Mimikatz used for credential harvesting post-exploitation; monitor for Mimikatz execution or LSASS memory access.
  • Ransomware appends extensions .mallox, .exploit, .avast, .consultransom to encrypted files; use file extension monitoring to detect encryption activity.
  • Initial access via malicious OneNote files used in spam campaigns (Xollam variant); monitor for OneNote files spawning child processes.
  • ·CVE-2019-1069 is listed in CISA KEV as confirmed exploited in the wild (historically), but MSRC's own exploit status at time of patch listed it as 'Exploited: No' — inclusion in KEV reflects past confirmed use in attacks, not necessarily recent active exploitation.
  • ·MSRC exploit status at patch time was 'Publicly Disclosed: Yes; Exploited: No; Exploitation More Likely' for both latest and older software releases — defenders should treat exploitation likelihood as high despite the 'Exploited: No' flag at patch time.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.