Zero-Day Exploit Code Released for Windows Task Scheduler Flaw (CVE-2024-49039), Actively Exploited by RomCom Group

Share:

A proof-of-concept (PoC) exploit code for CVE-2024-49039, a zero-day vulnerability in Windows Task Scheduler, has been publicly released, raising concerns about increased attacks. This vulnerability, with a CVSS score of 8.8, allows attackers to escalate privileges and execute code at a higher integrity level.

Vulnerability Details:

CVE-2024-49039 enables attackers to bypass security restrictions and execute arbitrary code with elevated privileges. This flaw resides in the Windows Task Scheduler service, a critical component responsible for scheduling and automating tasks. By exploiting this vulnerability, attackers can gain a foothold in the system and potentially take complete control.

Exploitation in the Wild:

The RomCom cybercrime group, known for its sophisticated attacks, has been observed actively exploiting this zero-day vulnerability in recent campaigns targeting Firefox and Tor Browser users across Europe and North America. These attacks involve chaining CVE-2024-49039 with another zero-day (CVE-2024-9680) in Firefox to achieve code execution outside the browser’s sandbox.

Technical Analysis:

The vulnerability likely stems from a flaw in the WPTaskScheduler.dll component, which is integral to Task Scheduler since Windows 10 version 1507. Analysis suggests that this vulnerability allows attackers to bypass security measures like Restricted Token Sandbox and child-process restrictions, effectively elevating their privileges to a Medium Integrity level.

PoC Availability and Impact:

The release of PoC code on Github further amplifies the risk, as it provides malicious actors with a readily available tool to exploit CVE-2024-49039. This situation necessitates immediate action from users and organizations to mitigate potential threats.

Mitigation:

Microsoft addressed this vulnerability with a security update released on November 12th. Users are strongly urged to apply this update as soon as possible to protect their systems. Additionally, maintaining updated software and exercising caution when opening suspicious emails or clicking on unknown links can help prevent falling victim to such attacks.

do son

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:03 am, Apr 21, 2025
weather icon 13°C
L: 11° | H: 16°
scattered clouds
Humidity: 82 %
Pressure: 1009 mb
Wind: 1 mph
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:51 am
Sunset: 8:06 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
11° | 16°°C 1 mm 100% 11 mph 81 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
8° | 16°°C 0 mm 0% 11 mph 86 % 1017 mb 0 mm/h
Wed Apr 23 10:00 pm
weather icon
8° | 12°°C 1 mm 100% 13 mph 95 % 1016 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
9° | 15°°C 0.2 mm 20% 5 mph 86 % 1022 mb 0 mm/h
Fri Apr 25 10:00 pm
weather icon
9° | 17°°C 0 mm 0% 8 mph 87 % 1022 mb 0 mm/h
Today 1:00 pm
weather icon
13° | 14°°C 0 mm 0% 7 mph 74 % 1009 mb 0 mm/h
Today 4:00 pm
weather icon
14° | 15°°C 1 mm 100% 11 mph 72 % 1009 mb 0 mm/h
Today 7:00 pm
weather icon
12° | 12°°C 1 mm 100% 8 mph 74 % 1011 mb 0 mm/h
Today 10:00 pm
weather icon
10° | 10°°C 0 mm 0% 6 mph 81 % 1013 mb 0 mm/h
Tomorrow 1:00 am
weather icon
9° | 9°°C 0 mm 0% 7 mph 84 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
8° | 8°°C 0 mm 0% 5 mph 86 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
8° | 8°°C 0 mm 0% 5 mph 84 % 1016 mb 0 mm/h
Tomorrow 10:00 am
weather icon
12° | 12°°C 0 mm 0% 6 mph 63 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€76,509.75
3.49%
Ethereum(ETH)
€1,436.48
3.23%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.86
3.19%
Solana(SOL)
€122.55
0.71%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.141897
4.59%
Shiba Inu(SHIB)
€0.000011
3.35%
Pepe(PEPE)
€0.000007
6.27%
Scroll to Top