CVE-2019-1069
published 2019-06-12CVE-2019-1069: An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited…
PriorityP184high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-05
Exploited in the wild
EPSS
6.12%
92.6th percentile
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system.
To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system.
The security update addresses the vulnerability by correctly validating file operations.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < publication | publication |
| microsoft | windows_10_version_1703 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < publication | publication |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_10_version_1709 | — | — |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1903 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_version_1803 | — | — |
| msrc | windows_server_version_1903 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2019-1069 exploited by TargetCompany ransomware as an initial access / privilege escalation vector alongside CVE-2020-0618; look for Task Scheduler Service abuse by unprivileged processes. ↗
- →Post-exploitation chain involves a PowerShell script downloading a malicious file from a C&C server and executing it via WMIC; monitor for WMIC spawning processes from PowerShell-downloaded payloads. ↗
- →Reflective loading observed: PowerShell script downloads a .NET downloader which retrieves an encrypted payload from C&C, decrypted via XOR or inversion and executed in-memory; monitor for in-memory .NET assembly loading from PowerShell. ↗
- →Attackers manually uninstall AV products using GMER and Advance Process Termination tools; alert on execution of these tools in enterprise environments. ↗
- →Mimikatz used for credential harvesting post-exploitation; monitor for Mimikatz execution or LSASS memory access. ↗
- →Ransomware appends extensions .mallox, .exploit, .avast, .consultransom to encrypted files; use file extension monitoring to detect encryption activity. ↗
- →Initial access via malicious OneNote files used in spam campaigns (Xollam variant); monitor for OneNote files spawning child processes. ↗
- ·CVE-2019-1069 is listed in CISA KEV as confirmed exploited in the wild (historically), but MSRC's own exploit status at time of patch listed it as 'Exploited: No' — inclusion in KEV reflects past confirmed use in attacks, not necessarily recent active exploitation. ↗
- ·MSRC exploit status at patch time was 'Publicly Disclosed: Yes; Exploited: No; Exploitation More Likely' for both latest and older software releases — defenders should treat exploitation likelihood as high despite the 'Exploited: No' flag at patch time. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gf8w-3v8h-w6hr: An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations, aka 'Task Scheduler Elevation
ghsa_unreviewed·2022-05-24
CVE-2019-1069 [HIGH] CWE-59 GHSA-gf8w-3v8h-w6hr: An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations, aka 'Task Scheduler Elevation
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations, aka 'Task Scheduler Elevation of Privilege Vulnerability'.
VulnCheck
Microsoft Task Scheduler Privilege Escalation Vulnerability
vulncheck·2019·CVSS 7.8
CVE-2019-1069 [HIGH] CWE-59 Microsoft Task Scheduler Privilege Escalation Vulnerability
Microsoft Task Scheduler Privilege Escalation Vulnerability
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
Affected: Microsoft Task Scheduler
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.advintel.io/post/adversary-dossier-ryuk-ransomware-anatomy-of-an-attack-in-2021; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.tenable.com/blog/contileaks-chats-reveal-over-30-vulnerabilities-used-by-conti-ransomware-affiliates; https://www.securin.io/articles/all-about-conti-ransomware/; https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-targetcompany
Remed
CISA
Microsoft Task Scheduler Privilege Escalation Vulnerability
cisa·2022-03-15·CVSS 7.8
CVE-2019-1069 [HIGH] CWE-59 Microsoft Task Scheduler Privilege Escalation Vulnerability
Vulnerability: Microsoft Task Scheduler Privilege Escalation Vulnerability
Affected: Microsoft Task Scheduler
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1069
Remediation Due Date: 2022-04-05
Microsoft
Task Scheduler Elevation of Privilege Vulnerability
vendor_msrc·2019-06-11·CVSS 7.8
CVE-2019-1069 [HIGH] Task Scheduler Elevation of Privilege Vulnerability
Task Scheduler Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system.
To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system.
The security update addresses the vulnerability by correctly validating file operations.
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.upda
No detection rules found.
No public exploits indexed.
Bleepingcomputer
CISA warns of actively exploited Apache HugeGraph-Server bug
blogs_bleepingcomputer·2024-09-19·CVSS 8.8
CVE-2024-27348 [HIGH] CISA warns of actively exploited Apache HugeGraph-Server bug
## CISA warns of actively exploited Apache HugeGraph-Server bug
## Bill Toulas
The U.S. Cybersecurity and Infrastructure Agency (CISA) has added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, among which is a remote code execution (RCE) flaw impacting Apache HugeGraph-Server.
The flaw, tracked as CVE-2024-27348 and rated critical (CVSS v3.1 score: 9.8), is an improper access control vulnerability that impacts HugeGraph-Server versions from 1.0.0 and up to, but not including 1.3.0.
Apache fixed the vulnerability on April 22, 2024, with the release of version 1.3.0. Apart from upgrading to the latest version, users were also recommended to use Java 11 and enable the Auth system .
Also, enabling the "Whitelist-IP/port" function was proposed to improve the security of th
Trendmicro
TargetCompany unter der Lupe
blogs_trendmicro·2023-06-28
TargetCompany unter der Lupe
Ransomware
## TargetCompany unter der Lupe
TargetCompany ist eine Ransomware-Familie mit vielen verschiedenen Erscheinungsformen, die sich in der Bedrohungslandschaft etabliert hat. Deshalb ist die Kenntnis der Einzelheiten dieser schillernden Malware für den Schutz davor wichtig.
By: Trend Micro Jun 28, 2023 Read time: ( words)
Save to Folio
Die Ransomware TargetCompany wurde im Juni 2021 entdeckt und von Branchenanalysten nach dem Muster benannt, nach dem die verschlüsselten Dateien an den Namen des Zielunternehmens angehängt werden. In einem Interview im Januar 2023 stellten die Bedrohungsakteure hinter TargetCompany klar, dass jedes größere Update der Ransomware eine Änderung des Verschlüsselungsalgorithmus und verschiedene Entschlüsselungsmerkmale mit sich bringt. Diese gehen mit
Tenable
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
blogs_tenable·2022-03-24
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
Exploit Developer Spotlight: The Story of PlayBit
blogs_checkpoint·2020-10-26·CVSS 7.8
CVE-2018-8453 [HIGH] Exploit Developer Spotlight: The Story of PlayBit
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Exploit Developer Spotlight: The Story of PlayBit
Research By: Eyal Itkin and Itay Cohen
## Introduction
Exploits have always been an important and integral part of malicious attacks.
Checkpoint
Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
blogs_checkpoint·2020-10-02
CVE-2019-0859 Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
Research by: Itay Cohen, Eyal Itkin
In the past months, our Vulnerability and Malware Research tea
Securelist
IT threat evolution Q2 2019. Statistics
blogs_securelist·2019-08-19
IT threat evolution Q2 2019. Statistics
Table of Contents
- Quarterly figures
- Mobile threats
- Attacks on Apple macOS
- IoT attacks
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyber attacks
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Boris Larin
- Oleg Kupreev
- Evgeny Lopatin
These statistics are based on detection verdicts of Kaspersky products received from users who consented to provide statistical data.
## Quarterly figures
According to Kaspersky Security Network,
- Kaspersky solutions blocked 717,057,912 attacks launched from online resources in 203 countries across the globe.
- 217,843,293 unique URLs triggered Web Anti-Virus components.
- Attempted infections by malware designed to steal money via online access to bank accounts were
Krebs
Microsoft Patch Tuesday, June 2019 Edition
blogs_krebs·2019-06-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, June 2019 Edition
Microsoft on Tuesday released updates to fix 88 security vulnerabilities in its Windows operating systems and related software. The most dangerous of these include four flaws for which there is already exploit code available. There’s also a scary bug affecting all versions of Microsoft Office that can be triggered by a malicious link or attachment. And of course Adobe has its customary monthly security update for Flash Player .
Microsoft says it has so far seen no exploitation against any of the four flaws that were disclosed publicly prior to their patching this week — nor against any of the 88 bugs quashed in this month’s release. All four are privilege escalation flaws: CVE-2019-1064 and CVE-2019-1069 affect Windows 10 and later; CVE-2019-1053 and CVE-2019-0973 both affect all currentl
Tenable
Tenable Roundup for Microsoft's June 2019 Patch Tuesday
blogs_tenable·2019-06-11
Tenable Roundup for Microsoft's June 2019 Patch Tuesday
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
Zscaler found Multiple Security Vulnerabilities | 06-11-2019
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Multiple Security Vulnerabilities | 06-11-2019
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1069https://blog.0patch.com/2019/06/another-task-scheduler-0day-another.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1069https://www.kb.cert.org/vuls/id/119704https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1069
2019-06-12
Published
2022-03-15
Added to CISA KEV
Exploited in the wild