CVE-2024-49039

HIGH KEV RANSOMWARE

Windows 10 1507-22H2 and Windows 11 22H2 - Elevation of Privilege via Task Scheduler

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-49039 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 12, 2024, with confirmed use in ransomware campaigns. EIP tracks 2 public exploits from researchers including je5442804, razureink.

AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2024-49039, targeting a vulnerability in WPTaskScheduler.dll (Task Scheduler component) that allows bypassing restricted token sandboxes and elevating to Medium Integrity. The exploit leverages RPC interface manipulation and includes reflective DLL injection capabilities.

Description

Windows Task Scheduler Elevation of Privilege Vulnerability

Exploits (2)

nomisec WORKING POC 135 stars
by je5442804 · local
https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039

This repository contains a functional exploit PoC for CVE-2024-49039, targeting a vulnerability in WPTaskScheduler.dll (Task Scheduler component) that allows bypassing restricted token sandboxes and elevating to Medium Integrity. The exploit leverages RPC interface manipulation and includes reflective DLL injection capabilities.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Windows Task Scheduler (WPTaskScheduler.dll) on Windows 10/11 and Server 2016/2019
No auth needed
Prerequisites: Access to a restricted token process (e.g., Chrome renderer, GPU process) · Windows 10/11 or Server 2016/2019 with vulnerable WPTaskScheduler.dll
mistral-large-3 · analyzed Feb 18, 2026 Full analysis →
github WORKING POC
by razureink · pythonpoc
https://github.com/razureink/cve-2024-49039-task_scheduler_eop_reproduction

This PoC exploits CVE-2024-49039, a Windows Task Scheduler Elevation of Privilege vulnerability (CWE-287) allowing AppContainer escape via improper authentication in the Task Scheduler RPC interface. The exploit creates a scheduled task with Medium integrity privileges using COM or schtasks.exe.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Windows Task Scheduler (all Windows versions prior to November 2024 security update)
Auth required
Prerequisites: Low integrity context (e.g., AppContainer) · Target system unpatched (pre-November 2024 updates) · Python with comtypes library installed
mistral-large-3 · analyzed Jul 23, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.1372
EPSS Percentile 96.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2024-11-12
VulnCheck KEV 2024-11-12
InTheWild.io 2024-11-12
ENISA EUVD EUVD-2024-43910
Ransomware Use Confirmed
CWE
CWE-287
Status published
Products (13)
microsoft/windows_10_1507 < 10.0.10240.20826 (2 CPE variants)
microsoft/windows_10_1607 < 10.0.14393.7515 (2 CPE variants)
microsoft/windows_10_1809 < 10.0.17763.6532 (2 CPE variants)
microsoft/windows_10_21h2 < 10.0.19044.5131 (3 CPE variants)
microsoft/windows_10_22h2 < 10.0.19045.5131 (3 CPE variants)
microsoft/windows_11_22h2 < 10.0.22621.4460 (2 CPE variants)
microsoft/windows_11_23h2 < 10.0.22631.4460 (2 CPE variants)
microsoft/windows_11_24h2 < 10.0.26100.2314 (2 CPE variants)
microsoft/windows_server_2016 < 10.0.14393.7515
microsoft/windows_server_2019 < 10.0.17763.6532
... and 3 more
Published Nov 12, 2024
KEV Added Nov 12, 2024
Tracked Since Feb 18, 2026