Zero-Day Exploit Code Released for Windows Task Scheduler Flaw (CVE-2024-49039), Actively Exploited by RomCom Group

Share:

A proof-of-concept (PoC) exploit code for CVE-2024-49039, a zero-day vulnerability in Windows Task Scheduler, has been publicly released, raising concerns about increased attacks. This vulnerability, with a CVSS score of 8.8, allows attackers to escalate privileges and execute code at a higher integrity level.

Vulnerability Details:

CVE-2024-49039 enables attackers to bypass security restrictions and execute arbitrary code with elevated privileges. This flaw resides in the Windows Task Scheduler service, a critical component responsible for scheduling and automating tasks. By exploiting this vulnerability, attackers can gain a foothold in the system and potentially take complete control.

Exploitation in the Wild:

The RomCom cybercrime group, known for its sophisticated attacks, has been observed actively exploiting this zero-day vulnerability in recent campaigns targeting Firefox and Tor Browser users across Europe and North America. These attacks involve chaining CVE-2024-49039 with another zero-day (CVE-2024-9680) in Firefox to achieve code execution outside the browser’s sandbox.

Technical Analysis:

The vulnerability likely stems from a flaw in the WPTaskScheduler.dll component, which is integral to Task Scheduler since Windows 10 version 1507. Analysis suggests that this vulnerability allows attackers to bypass security measures like Restricted Token Sandbox and child-process restrictions, effectively elevating their privileges to a Medium Integrity level.

PoC Availability and Impact:

The release of PoC code on Github further amplifies the risk, as it provides malicious actors with a readily available tool to exploit CVE-2024-49039. This situation necessitates immediate action from users and organizations to mitigate potential threats.

Mitigation:

Microsoft addressed this vulnerability with a security update released on November 12th. Users are strongly urged to apply this update as soon as possible to protect their systems. Additionally, maintaining updated software and exercising caution when opening suspicious emails or clicking on unknown links can help prevent falling victim to such attacks.

do son

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:16 pm, Feb 8, 2025
weather icon 5°C
L: 4° | H: 6°
overcast clouds
Humidity: 92 %
Pressure: 1018 mb
Wind: 10 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 2 km
Sunrise: 7:27 am
Sunset: 5:02 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
4° | 6°°C 0.2 mm 20% 6 mph 93 % 1023 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 7°°C 1 mm 100% 10 mph 97 % 1031 mb 0 mm/h
Mon Feb 10 9:00 pm
weather icon
3° | 5°°C 0.2 mm 20% 11 mph 95 % 1031 mb 0 mm/h
Tue Feb 11 9:00 pm
weather icon
3° | 7°°C 1 mm 100% 6 mph 98 % 1022 mb 0 mm/h
Wed Feb 12 9:00 pm
weather icon
4° | 9°°C 0 mm 0% 10 mph 97 % 1027 mb 0 mm/h
Today 3:00 pm
weather icon
5° | 6°°C 0.2 mm 20% 6 mph 93 % 1018 mb 0 mm/h
Today 6:00 pm
weather icon
5° | 5°°C 0 mm 0% 5 mph 82 % 1020 mb 0 mm/h
Today 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 4 mph 81 % 1023 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 3°°C 0 mm 0% 5 mph 87 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 6 mph 87 % 1025 mb 0 mm/h
Tomorrow 6:00 am
weather icon
4° | 4°°C 0.89 mm 89% 8 mph 97 % 1026 mb 0 mm/h
Tomorrow 9:00 am
weather icon
4° | 4°°C 1 mm 100% 9 mph 96 % 1028 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
6° | 6°°C 1 mm 100% 10 mph 88 % 1029 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,081.62
-1.54%
Ethereum(ETH)
€2,530.67
-5.09%
Tether(USDT)
€0.97
-0.04%
XRP(XRP)
€2.33
0.06%
Solana(SOL)
€187.79
-1.97%
USDC(USDC)
€0.97
0.01%
Dogecoin(DOGE)
€0.240031
-2.47%
Shiba Inu(SHIB)
€0.000015
2.96%
Pepe(PEPE)
€0.000009
-3.03%
Scroll to Top