Zero-Day Exploit Code Released for Windows Task Scheduler Flaw (CVE-2024-49039), Actively Exploited by RomCom Group

Share:

A proof-of-concept (PoC) exploit code for CVE-2024-49039, a zero-day vulnerability in Windows Task Scheduler, has been publicly released, raising concerns about increased attacks. This vulnerability, with a CVSS score of 8.8, allows attackers to escalate privileges and execute code at a higher integrity level.

Vulnerability Details:

CVE-2024-49039 enables attackers to bypass security restrictions and execute arbitrary code with elevated privileges. This flaw resides in the Windows Task Scheduler service, a critical component responsible for scheduling and automating tasks. By exploiting this vulnerability, attackers can gain a foothold in the system and potentially take complete control.

Ezoic
Exploitation in the Wild:

The RomCom cybercrime group, known for its sophisticated attacks, has been observed actively exploiting this zero-day vulnerability in recent campaigns targeting Firefox and Tor Browser users across Europe and North America. These attacks involve chaining CVE-2024-49039 with another zero-day (CVE-2024-9680) in Firefox to achieve code execution outside the browser’s sandbox.

Technical Analysis:

The vulnerability likely stems from a flaw in the WPTaskScheduler.dll component, which is integral to Task Scheduler since Windows 10 version 1507. Analysis suggests that this vulnerability allows attackers to bypass security measures like Restricted Token Sandbox and child-process restrictions, effectively elevating their privileges to a Medium Integrity level.

PoC Availability and Impact:

The release of PoC code on Github further amplifies the risk, as it provides malicious actors with a readily available tool to exploit CVE-2024-49039. This situation necessitates immediate action from users and organizations to mitigate potential threats.

Mitigation:

Microsoft addressed this vulnerability with a security update released on November 12th. Users are strongly urged to apply this update as soon as possible to protect their systems. Additionally, maintaining updated software and exercising caution when opening suspicious emails or clicking on unknown links can help prevent falling victim to such attacks.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
7:46 pm, Jan 16, 2025
weather icon 8°C
L: 7° | H: 8°
clear sky
Humidity: 87 %
Pressure: 1035 mb
Wind: 6 mph WSW
Wind Gust: 9 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:58 am
Sunset: 4:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
7° | 8°°C 0 mm 0% 4 mph 87 % 1035 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 4 mph 83 % 1034 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 7 mph 88 % 1023 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 7 mph 93 % 1021 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 8°°C 0 mm 0% 4 mph 87 % 1035 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 7°°C 0 mm 0% 3 mph 90 % 1035 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 5°°C 0 mm 0% 4 mph 93 % 1034 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 96 % 1035 mb 0 mm/h
Tomorrow 9:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 95 % 1035 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
7° | 7°°C 0 mm 0% 5 mph 77 % 1035 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 3 mph 76 % 1034 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
5° | 5°°C 0 mm 0% 3 mph 88 % 1034 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€96,984.35
0.26%
Ethereum(ETH)
€3,235.67
-2.49%
XRP(XRP)
€3.28
14.29%
Tether(USDT)
€0.97
-0.02%
Solana(SOL)
€206.86
5.41%
Dogecoin(DOGE)
€0.374538
2.27%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000021
0.63%
Pepe(PEPE)
€0.000017
-0.94%
Peanut the Squirrel(PNUT)
€0.59
-3.58%
Scroll to Top