HIGH
CVE-2024-49039
CVSS
8.8
KEV
Description
Windows Task Scheduler Elevation of Privilege Vulnerability
Summary dbcve.org
Windows Task Scheduler contains an elevation of privilege vulnerability that allows an authenticated attacker to gain SYSTEM-level privileges by exploiting how the Task Scheduler handles task creation or execution. The specific flaw permits a low-privilege user to manipulate scheduled tasks to run with elevated permissions.
Mitigation
Apply the Microsoft security update for CVE-2024-49039 to all affected Windows systems. Additionally, restrict user permissions for creating or modifying scheduled tasks to minimize attack surface until patching is complete.
Weakness (CWE)
CWE-287
Improper Authentication
EPSS Score
14.18%
Probability of exploitation in next 30 days
96.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.