Windows 10 Task Scheduler Zero-Day Vulnerability Exploit Leaked, Can Help Gain Admin-Level Access

The flaw is open for exploitation and remains unpatched.

Advertisement
By Nadeem Sarwar | Updated: 22 May 2019 14:28 IST
Highlights
  • The exploit can be tweaked to work on older versions of Windows
  • A proof-of-concept video has also been made public
  • Microsoft is yet to acknowledge the LPE vulnerability and fix it
Windows 10 Task Scheduler Zero-Day Vulnerability Exploit Leaked, Can Help Gain Admin-Level Access

The same researcher unearthed a zero-day vulnerability last year as well.

Windows 10 has been hit by yet another zero-day vulnerability that can allow malicious parties to gain admin-level privileges. The yet unnamed zero-day vulnerability can be exploited to break into a system and gain full control over it. The newly discovered threat to Microsoft's operating system can be classified as a Local Privilege Escalation (LPE) that can help hackers change the privilege level of an account to admin level, and it is associated with the native Task Scheduler process. The exploit can reportedly work on previous versions like Windows XP and Windows Server as well.

The vulnerability was spotted by a security researcher going by the name SandboxEscaper, the same person who also discovered another zero-day vulnerability affecting the Microsoft Data Sharing service last year. SandboxEscaper shared the demo exploit code for the vulnerability on Github, which is a little ironic since Github is owned by Microsoft, alongside a proof-of-concept video detailing the process of exploiting the flaw.

As mentioned above, the vulnerability is associated with the Windows Task Scheduler process wherein bad actors can run a malicious command to promote the account level from low-privilege to admin control level. Once admin access is achieved, the malicious party can gain control over the entire system and target other system files. Will Dormann, a vulnerability analyst at CERT, has confirmed that the exploit is functional even on the latest Windows 10 May 2019 build. The exploit affects 32-bit and 64-bit versions of Windows 10, Windows Server 2016 and Windows Server 2019.

Theoretically, the flaw can reportedly be exploited on all versions of Windows such as Windows XP, and dating all the way back to Windows Server 2003. The vulnerability is yet to be patched, which means it is open to exploit. SandboxEscaper also claims to have discovered four more unpatched Windows bugs, with three of them being LPEs and the last one being associated with the Sandbox process.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple Announces iOS 26 With Liquid Glass Design, These New Features
  2. iQOO 13 and More Available With Discounts During iQOO 5th Anniversary Sale
  3. Everything We Know About the Vivo T4 Ultra Ahead of Its June 11 Launch
  4. WWDC 2025 Highlights: Apple Unveils iOS 26, macOS 26 and Liquid Glass UI
  5. Poco F7 India Launch Teased; Flipkart Availability Confirmed
  6. Samsung Galaxy Z Fold 7, Z Flip 7 Unpacked Event Said to Be Held Mid-July
  7. WWDC 2025: Apple Announces watchOS 26 With Major Overhaul
  8. Apple Unveils iPadOS 26 With New Windowing System at WWDC 2025
  9. WhatApp May Soon Let You Choose Media Auto-Download Quality on Android
  10. AI+ Smartwatch With Built-in TWS Launching This Month: Report
  1. WWDC 2025: watchOS 26 Offers AI Workout Buddy, Wrist Flick Gesture, Liquid Glass Design, and More
  2. WWDC 2025: Apple Unveils iPadOS 26 With New Windowing System, Liquid Glass UI, and More
  3. WWDC 2025: macOS Tahoe 26 Unveiled With New Design, Continuity Features and Big Update to Spotlight
  4. WWDC 2025: Apple Announces iOS 26 With New Liquid Glass Design, Apple Intelligence Enhancements and More
  5. WWDC 2025: Apple Intelligence Models Expanded to Developers, Live Translation Feature Unveiled
  6. Xbox Chief Phil Spencer Hints at 'Return' of Halo: Combat Evolved Next Year
  7. Vivo X Fold 5 Design Teased; Confirmed to Feature 8T LTPO Panels, Meet IP5X and IPX9+ Certifications
  8. Oppo K13x 5G Price Range in India Tipped; Alleged Retail Box Suggests Flat Display
  9. WWDC 2025: Apple Faces AI, Regulatory Challenges As it Woos Developers at Annual Conference
  10. WazirX Parent Zettai Urges Singapore Court to Review WazirX Restructuring, Extend Moratorium
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.