Blog | G5 Cyber Security

Zero-Day Flaw in Windows 10 Task Scheduler Gets Micropatch

An unpatched local privilege escalation zero-day vulnerability in Windows 10 received a temporary patch today. The fix is delivered through the 0patch platform and can be applied on systems without rebooting them. The problem stems from legacy support of task files, which can be added to a modern system from an old one. An attacker can use this bug after they compromised the target host to take control of files reserved for high-privilege users such as SYSTEM and TrustedInstaller. This way, they can act with increased rights on vulnerable systems.

Source: https://www.bleepingcomputer.com/news/security/zero-day-flaw-in-windows-10-task-scheduler-gets-micropatch/

Exit mobile version