{"id":1519,"date":"2018-09-04T14:30:41","date_gmt":"2018-09-04T14:30:41","guid":{"rendered":"https:\/\/www.varutra.com\/blog\/?p=1519"},"modified":"2023-03-24T12:27:43","modified_gmt":"2023-03-24T06:57:43","slug":"advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/","title":{"rendered":"Advisory | Microsoft Zero Day &#8211; Windows Task Scheduler Local Privilege Escalation Vulnerability"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"aaaaaaaaaaaaaaaaaaa - Varutra Consulting\"><\/p>\n<h3 style=\"text-align: left\"><strong>Introduction to Microsoft Zero Day Vulnerability<\/strong><\/h3>\n<p style=\"text-align: left\">A previously unknown zero day vulnerability has been disclosed in the Microsoft&#8217;s Windows operating system that could help a local user or malicious program to obtain system privileges on the targeted machine.<\/p>\n<p style=\"text-align: left\">The vulnerability is a privilege escalation issue which resides in the Windows&#8217; task scheduler program and occurred due to errors in the handling of Advanced Local Procedure Call (ALPC) systems.<\/p>\n<p style=\"text-align: left\">Advanced local procedure call (ALPC) is an internal mechanism, available only to Windows operating system components, that facilitates high-speed and secure data transfer between one or more processes in the user mode.<\/p>\n<p style=\"text-align: left\">Exploit for this vulnerability has been shared by a hacker named \u201cSandboxEscaper\u201d and the exploit code is currently available on public repositories like GitHub. However the current exploit works only in windows 64 bit operating systems. For a complete solution, we have to wait for Microsoft to respond until the scheduled September 11 Patch.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Affected Versions<\/strong><\/h3>\n<p>1) Windows 10<\/p>\n<p>2) Windows Server 2016<\/p>\n<p>The exploit would need modifications to work on operating systems other than 64-bit (i.e., 32-bit OS). Also it hard codes prnms003 driver, which doesn\u2019t exist in certain versions (e.g. on Windows 7 it can be prnms001). Compatibility with other windows versions may be possible with modification of the publicly available exploit source code.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>How to Detect?<\/strong><\/h3>\n<p>It is possible that the original windows processes can be replaced\u00a0with the malicious program shared by the hacker. So we can detect those exploits by checking whether the original windows processes have been replaced.<\/p>\n<ol>\n<li>Look for\u00a0<strong>spoolsv.exe\u00a0<\/strong>under abnormal processes (or another Spooler exploit).<\/li>\n<li>Look for\u00a0<strong>connhost.exe<\/strong> under abnormal processes (e.g. the Print Spooler).<\/li>\n<\/ol>\n<p><strong><u>Spoolsv.exe:<\/u><\/strong><\/p>\n<p>It is called Windows Print Spooler. This service spools print jobs and handles interaction with the printer. By disabling the Windows Print Spooler service you wouldn\u2019t be able to print more than one document at a time, and any documents not immediately sent to the printer wouldn\u2019t print.<\/p>\n<p><strong>Risk: <\/strong>If you turn off this service, you won\u2019t be able to print or see your printers.<\/p>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/ddddddddddddddddddddd.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1523 size-large\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/ddddddddddddddddddddd-1024x729.png\" alt=\"Checking for suspicious processes of Microsoft Zero day\" width=\"540\" height=\"384\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/ddddddddddddddddddddd-1024x729.png 1024w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/ddddddddddddddddddddd-300x214.png 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/ddddddddddddddddddddd-768x547.png 768w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/ddddddddddddddddddddd.png 1270w\" sizes=\"(max-width: 540px) 100vw, 540px\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Fig: Checking for suspicious processes<\/em><\/p>\n<p><strong><u>Connhost.exe:<\/u><\/strong><\/p>\n<p>It is called Console Windows Host. This service is present in Windows 10 and using this, windows command prompt can show the same window frame like the other programs. It also allows you to operate the cmd prompt and users to drag and drop a file directly into it.\u00a0This Microsoft Console Host program resides in &#8220;C:\\Windows\\System32&#8221; and should not be removed.<\/p>\n<p>This process is closely related to windows CSRSS(Client Server Runtime System Service) a protected process you can\u2019t terminate, which is responsible for console windows\u00a0and the shutdown process, which are critical functions in Windows.<\/p>\n<p><strong>Risk: <\/strong>If you turn off this service, windows CSRSS service will also crash because conhost.exe runs under csrss.exe, so there is a high chance for the system to become unusable or shutdown.<\/p>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/eeeeeeeeeeeeeeeeeeeeeeeeeee.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1524 size-large\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/eeeeeeeeeeeeeeeeeeeeeeeeeee-1024x724.png\" alt=\"Checking for suspicious processes\" width=\"540\" height=\"382\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Fig: Checking for suspicious processes<\/em><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Recommendations for Microsoft Zero Day Vulnerability<\/strong><\/h3>\n<ol>\n<li>Do not remove\/disable any original system processes without confirmation.<\/li>\n<li>Monitor and block any local users from gaining administrator privileges by using SIEM tools.<\/li>\n<li>Detect all the malicious processes by the name of genuine ones by using Behavioral Analysis.<\/li>\n<li>Network traffic analytics should continue to be used to detect anomalous traffic going across the network and to spot where users are behaving in a way that they historically don\u2019t.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: left\"><strong>References<\/strong><\/h3>\n<ol>\n<li style=\"text-align: left\"><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/906424\"> https:\/\/www.kb.cert.org\/vuls\/id\/906424<\/a><\/li>\n<li style=\"text-align: left\"><a href=\"https:\/\/doublepulsar.com\/task-scheduler-alpc-exploit-high-level-analysis-ff08cda6ad4f\">https:\/\/doublepulsar.com\/task-scheduler-alpc-exploit-high-level-analysis-ff08cda6ad4f<\/a><\/li>\n<li style=\"text-align: left\"><a href=\"https:\/\/threatpost.com\/microsoft-windows-zero-day-found-in-task-scheduler\/136977\/\">https:\/\/threatpost.com\/microsoft-windows-zero-day-found-in-task-scheduler\/136977\/<\/a><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Author,<\/p>\n<div><strong>Jinto T.K.<\/strong><\/div>\n<div>SOC Team<\/div>\n<div><em>Varutra Consulting Pvt. Ltd.<\/em><\/div>","protected":false},"excerpt":{"rendered":"<p>Introduction to Microsoft Zero Day Vulnerability A previously unknown zero day vulnerability has been disclosed in the Microsoft&#8217;s Windows operating system that could help a&#8230;<\/p>\n","protected":false},"author":3,"featured_media":2982,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[266,274,57,283],"tags":[123,125,126,127,128,129,130],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.7.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"Microsoft Zero Day privilege escalation vulnerability issue which resides in the task scheduler program and occurred due to errors in the handling of ALPC.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"kalpadmin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.7.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Microsoft Zero Day Windows Task Scheduler Vulnerability\" \/>\n\t\t<meta property=\"og:description\" content=\"Microsoft Zero Day privilege escalation vulnerability issue which resides in the task scheduler program and occurred due to errors in the handling of ALPC.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"700\" \/>\n\t\t<meta property=\"og:image:height\" content=\"467\" \/>\n\t\t<meta property=\"article:section\" content=\"Security Advisory\" \/>\n\t\t<meta property=\"article:tag\" content=\"advanced local procedure call (alpc)\" \/>\n\t\t<meta property=\"article:tag\" content=\"recommendation\" \/>\n\t\t<meta property=\"article:tag\" content=\"sandboxescaper\" \/>\n\t\t<meta property=\"article:tag\" content=\"security advisory\" \/>\n\t\t<meta property=\"article:tag\" content=\"windows 10\" \/>\n\t\t<meta property=\"article:tag\" content=\"windows privilege escalation\" \/>\n\t\t<meta property=\"article:tag\" content=\"zero day attack\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2018-09-04T14:30:41+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-03-24T06:57:43+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Microsoft Zero Day Windows Task Scheduler Vulnerability\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Microsoft Zero Day privilege escalation vulnerability issue which resides in the task scheduler program and occurred due to errors in the handling of ALPC.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpadmin\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#article\",\"name\":\"Microsoft Zero Day Windows Task Scheduler Vulnerability\",\"headline\":\"Advisory | Microsoft Zero Day &#8211; Windows Task Scheduler Local Privilege Escalation Vulnerability\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2018\\\/09\\\/aaaaaaaaaaaaaaaaaaa-1.jpg\",\"width\":700,\"height\":467,\"caption\":\"aaaaaaaaaaaaaaaaaaa\"},\"datePublished\":\"2018-09-04T14:30:41+05:30\",\"dateModified\":\"2023-03-24T12:27:43+05:30\",\"inLanguage\":\"en-US\",\"commentCount\":18,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#webpage\"},\"articleSection\":\"Security Advisory, Security Hardening, Vulnerability Disclosure, Zero Day Attack, Advanced Local Procedure Call (ALPC), Recommendation, SandboxEscaper, Security Advisory, Windows 10, Windows Privilege Escalation, Zero Day Attack\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/vulnerability-disclosure\\\/#listItem\",\"name\":\"Vulnerability Disclosure\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/vulnerability-disclosure\\\/#listItem\",\"position\":2,\"name\":\"Vulnerability Disclosure\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/vulnerability-disclosure\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#listItem\",\"name\":\"Advisory | Microsoft Zero Day &#8211; Windows Task Scheduler Local Privilege Escalation Vulnerability\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#listItem\",\"position\":3,\"name\":\"Advisory | Microsoft Zero Day &#8211; Windows Task Scheduler Local Privilege Escalation Vulnerability\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/vulnerability-disclosure\\\/#listItem\",\"name\":\"Vulnerability Disclosure\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/\",\"name\":\"kalpadmin\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/\",\"name\":\"Microsoft Zero Day Windows Task Scheduler Vulnerability\",\"description\":\"Microsoft Zero Day privilege escalation vulnerability issue which resides in the task scheduler program and occurred due to errors in the handling of ALPC.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2018\\\/09\\\/aaaaaaaaaaaaaaaaaaa-1.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#mainImage\",\"width\":700,\"height\":467,\"caption\":\"aaaaaaaaaaaaaaaaaaa\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\\\/#mainImage\"},\"datePublished\":\"2018-09-04T14:30:41+05:30\",\"dateModified\":\"2023-03-24T12:27:43+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Microsoft Zero Day Windows Task Scheduler Vulnerability<\/title>\n\n","aioseo_head_json":{"title":"Microsoft Zero Day Windows Task Scheduler Vulnerability","description":"Microsoft Zero Day privilege escalation vulnerability issue which resides in the task scheduler program and occurred due to errors in the handling of ALPC.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#article","name":"Microsoft Zero Day Windows Task Scheduler Vulnerability","headline":"Advisory | Microsoft Zero Day &#8211; Windows Task Scheduler Local Privilege Escalation Vulnerability","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg","width":700,"height":467,"caption":"aaaaaaaaaaaaaaaaaaa"},"datePublished":"2018-09-04T14:30:41+05:30","dateModified":"2023-03-24T12:27:43+05:30","inLanguage":"en-US","commentCount":18,"mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#webpage"},"articleSection":"Security Advisory, Security Hardening, Vulnerability Disclosure, Zero Day Attack, Advanced Local Procedure Call (ALPC), Recommendation, SandboxEscaper, Security Advisory, Windows 10, Windows Privilege Escalation, Zero Day Attack"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/#listItem","name":"Vulnerability Disclosure"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/#listItem","position":2,"name":"Vulnerability Disclosure","item":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#listItem","name":"Advisory | Microsoft Zero Day &#8211; Windows Task Scheduler Local Privilege Escalation Vulnerability"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#listItem","position":3,"name":"Advisory | Microsoft Zero Day &#8211; Windows Task Scheduler Local Privilege Escalation Vulnerability","previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/#listItem","name":"Vulnerability Disclosure"}}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","description":"Secure your digital world with our Cybersecurity services.","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/","name":"kalpadmin","image":{"@type":"ImageObject","url":"https:\/\/secure.gravatar.com\/avatar\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/","name":"Microsoft Zero Day Windows Task Scheduler Vulnerability","description":"Microsoft Zero Day privilege escalation vulnerability issue which resides in the task scheduler program and occurred due to errors in the handling of ALPC.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#mainImage","width":700,"height":467,"caption":"aaaaaaaaaaaaaaaaaaa"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/#mainImage"},"datePublished":"2018-09-04T14:30:41+05:30","dateModified":"2023-03-24T12:27:43+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"Microsoft Zero Day Windows Task Scheduler Vulnerability","og:description":"Microsoft Zero Day privilege escalation vulnerability issue which resides in the task scheduler program and occurred due to errors in the handling of ALPC.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg","og:image:width":"700","og:image:height":"467","article:section":"Security Advisory","article:tag":["advanced local procedure call (alpc)","recommendation","sandboxescaper","security advisory","windows 10","windows privilege escalation","zero day attack"],"article:published_time":"2018-09-04T14:30:41+00:00","article:modified_time":"2023-03-24T06:57:43+00:00","twitter:card":"summary_large_image","twitter:title":"Microsoft Zero Day Windows Task Scheduler Vulnerability","twitter:description":"Microsoft Zero Day privilege escalation vulnerability issue which resides in the task scheduler program and occurred due to errors in the handling of ALPC.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg","twitter:label1":"Written by","twitter:data1":"kalpadmin","twitter:label2":"Est. reading time","twitter:data2":"3 minutes"},"aioseo_meta_data":{"post_id":"1519","title":"Microsoft Zero Day Windows Task Scheduler Vulnerability","description":"Microsoft Zero Day privilege escalation vulnerability issue which resides in the task scheduler program and occurred due to errors in the handling of ALPC.","keywords":[],"keyphrases":{"focus":{"keyphrase":"Microsoft Zero Day","score":90,"analysis":{"keyphraseInTitle":{"score":9,"maxScore":9,"error":0},"keyphraseInDescription":{"score":9,"maxScore":9,"error":0},"keyphraseLength":{"score":9,"maxScore":9,"error":0,"length":3},"keyphraseInURL":{"score":5,"maxScore":5,"error":0},"keyphraseInIntroduction":{"score":3,"maxScore":9,"error":1},"keyphraseInSubHeadings":{"score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"score":9,"maxScore":9,"error":0}}},"additional":[{"keyphrase":"Microsoft","score":83,"analysis":{"keyphraseInDescription":{"score":9,"maxScore":9,"error":0},"keyphraseLength":{"score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"score":9,"maxScore":9,"error":0}}},{"keyphrase":"Zero Day","score":100,"analysis":{"keyphraseInDescription":{"score":9,"maxScore":9,"error":0},"keyphraseLength":{"score":9,"maxScore":9,"error":0,"length":2},"keyphraseInIntroduction":{"score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"score":9,"maxScore":9,"error":0}}}]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/aaaaaaaaaaaaaaaaaaa-1.jpg","og_image_width":"700","og_image_height":"467","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Security Advisory","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"created":"2021-10-27 15:17:57","updated":"2026-05-24 09:18:18","ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-05-22 11:51:04"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/\" title=\"Vulnerability Disclosure\">Vulnerability Disclosure<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tAdvisory | Microsoft Zero Day \u2013 Windows Task Scheduler Local Privilege Escalation Vulnerability\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Vulnerability Disclosure","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/"},{"label":"Advisory | Microsoft Zero Day &#8211; Windows Task Scheduler Local Privilege Escalation Vulnerability","link":"https:\/\/www.varutra.com\/varutravrt3\/advisory-microsoft-zero-day-vulnerability-windows-task-scheduler-local-privilege-escalation-vulnerability\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/1519"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=1519"}],"version-history":[{"count":5,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/1519\/revisions"}],"predecessor-version":[{"id":21203,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/1519\/revisions\/21203"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/2982"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=1519"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=1519"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=1519"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}