Windows Task Scheduler Elevation of Privilege Vulnerability
Published: 2024-11-12
Microsoft addresses 87 CVEs and one advisory (ADV240001) in its November 2024 Patch Tuesday release, with four critical vulnerabilities and four zero-day vulnerabilities, including two that were exploited in the wild.
https://thehackernews.com/2025/04/google-reports-75-zero-days-exploited.html
https://www.helpnetsecurity.com/2024/11/26/romcom-backdoor-cve-2024-9680-cve-2024-49039/
https://thehackernews.com/2024/11/romcom-exploits-zero-day-firefox-and.html
https://securityaffairs.com/170851/hacking/microsoft-patch-tuesday-november-2024.html
https://www.helpnetsecurity.com/2024/11/12/cve-2024-43451-cve-2024-49039/
https://www.darkreading.com/cloud-security/2-zero-day-bugs-microsoft-nov-update-active-exploit
Published: 2024-11-12
Updated: 2024-11-14
Named Vulnerability: Windows Task Scheduler Elevation of Privilege VulnerabilityKnown Exploited Vulnerability (KEV)
Base Score: 6.8
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
Severity: Medium
Base Score: 8.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity: High
EPSS: 0.30614