Skip to main content

CVE-2019-1069

7.8
HIGHCVSS v3.1 Base Score
32.50%
MEDIUM RiskEPSS (97th percentile)
KEV

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.

Published: 6/12/2019
Modified: 10/29/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Microsoft Task Scheduler Privilege Escalation Vulnerability

Vendor / Product:

Microsoft Task Scheduler

Required Action:

Apply updates per vendor instructions.

Due Date: 4/5/2022(OVERDUE)
Ransomware Campaign Use
Added to KEV:

3/15/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2019-1069

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

32.50%MEDIUM Exploitation Risk
97th percentile

This vulnerability has a 32.50% probability of being exploited in the next 30 days, ranking higher than 97% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-59)

CVE-2026-41091HIGH 7.8

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

5/20/2026
CVE-2025-60710HIGH 7.8

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

11/11/2025
CVE-2025-48384HIGH 8

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.

7/8/2025
CVE-2025-21391HIGH 7.1

Windows Storage Elevation of Privilege Vulnerability

2/11/2025
CVE-2025-0377HIGH 7.5

HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.

1/21/2025

Similar SeverityHIGH