A zero-day vulnerability in Windows Task Scheduler is being exploited by a hacker group loosely called PowerPool, a nasty elevated privileges backdoor. The exploit is done through Advanced Local Procedure Call module, more particularly the SchRpcSetSecurity API. This creates a universal allow permission to write to C:WindowsTasks folder, regardless of the user privilege of the logged-in user. This weakness opens the Windows Task. Scheduler to be a platform to launch any type of user action, like installing software, running a program or launching a service.”]
Source: https://hackercombat.com/windows-task-managers-zero-day-vulnerability-detected-by-eset/

