(MS15-028) Vulnerability in Windows Task Scheduler Could Allow Security Feature Bypass (3030377)

  Severity: HIGH
  CVE Identifier: CVE-2015-0084
  Advisory Date: APR 02, 2015

  DESCRIPTION

This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow a user with limited privileges on an affected system to leverage Task Scheduler to execute files that they do not have permissions to run. An attacker who successfully exploited this vulnerability could bypass access control list (ACL) checks and run privileged executables.

  SOLUTION

  AFFECTED SOFTWARE AND VERSION

  • Windows 7 for 32-bit Systems Service Pack 1
  • Windows 7 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
  • Windows 8 for 32-bit Systems
  • Windows 8 for x64-based Systems
  • Windows 8.1 for 32-bit Systems
  • Windows 8.1 for x64-based Systems
  • Windows Server 2012
  • Windows Server 2012 R2
  • Windows RT
  • Windows RT 8.1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2 (Server Core installation)