Vulnerability Name: | CVE-2014-4074 (CCN-95542) | ||||||||
Assigned: | 2014-09-09 | ||||||||
Published: | 2014-09-09 | ||||||||
Updated: | 2019-05-13 | ||||||||
Summary: | The Task Scheduler in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via an application that schedules a crafted task, aka "Task Scheduler Vulnerability." | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.9 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-4074 Source: CCN Type: Microsoft Security Bulletin MS14-054 Vulnerability in Windows Task Scheduler Could Allow Elevation of Privilege (2988948) Source: CCN Type: Microsoft Security Bulletin MS15-102 Vulnerability in Windows Task Management Could Allow Elevation of Privilege (3089657) Source: BID Type: Third Party Advisory, VDB Entry 69593 Source: CCN Type: BID-69593 Microsoft Windows Task Scheduler Local Privilege Escalation Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1030820 Source: MS Type: Patch, Vendor Advisory MS14-054 Source: XF Type: Third Party Advisory, VDB Entry ms-task-scheduler-cve20144074-priv-esc(95542) Source: XF Type: UNKNOWN ms-task-scheduler-cve20144074-priv-esc(95542) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |