CVE-2024-49039

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 7 articles

EPSS Score

Source: FIRST.org · 2026-05-24
63.67%
probability
This CVE has a 63.67% probability of being exploited in the next 30 days.
0% Top 98.4th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Windows Task Scheduler Elevation of Privilege Vulnerability

Attack Intelligence

Google Project Zero

Patched
Nov. 12, 2024
Reported by
Vlad Stolyarov and Bahare Sabouri of Google's Threat Analysis Group
Root Cause Analysis
???

Signal Intelligence

Confidence
92%
EPSS 63.67%
Mentions 7
Last Seen Nov 26, 2024

CNA Information

Analyst Note

This CVE is confirmed as a zero-day vulnerability affecting Windows Server 2025's Task Scheduler with a HIGH severity rating (CVSS 8.8). The vulnerability was addressed in Microsoft's November 2024 Patch Tuesday and is documented by reputable sources including Google Project Zero and CERT-EU, with active exploitation reported by Russian threat actors.

Threat Actors 14

Turla Group
apt_group Information theft and espionage Russian Federation
Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
Careto
apt_group Information theft and espionage 🇪🇸 ES
Hacking Team
apt_group 🇮🇹 IT
Gamaredon Group
apt_group Information theft and espionage 🇷🇺 RU
ELECTRUM
apt_group Information theft and espionage 🇷🇺 RU
Group 27
apt_group Information theft and espionage 🇨🇳 CN
RomCom
apt_group Financial gain 🇷🇺 RU
Rocke
apt_group 🇨🇳 CN
Void Rabisu
apt_group Financial gain 🇷🇺 RU
Red Dev 17
apt_group 🇨🇳 CN
Red October
apt_group 🇷🇺 RU

Triage Info

Decided atMar 03, 2026