HIGH

CVE-2024-49039

Microsoft Windows 10 1507 2024-11-12 CVSS v3.1
CVSS
8.8
KEV

Description

Windows Task Scheduler Elevation of Privilege Vulnerability

Summary dbcve.org

Windows Task Scheduler contains an elevation of privilege vulnerability that allows an authenticated attacker to gain SYSTEM-level privileges by exploiting how the Task Scheduler handles task creation or execution. The specific flaw permits a low-privilege user to manipulate scheduled tasks to run with elevated permissions.

Mitigation

Apply the Microsoft security update for CVE-2024-49039 to all affected Windows systems. Additionally, restrict user permissions for creating or modifying scheduled tasks to minimize attack surface until patching is complete.

Patch Commit

Weakness (CWE)

CWE-287 Improper Authentication

EPSS Score

14.18%
Probability of exploitation in next 30 days
96.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE