Scheduled tasks can be listed from the command line using the schtasks  command without any options.

Untitled

To retrieve detailed information about any of the services, you can use a command like the following one:

schtasks /query /tn vulntask /fo list /v

Untitled

You will get lots of information about the task, but what matters for us is the "Task to Run" parameter which indicates what gets executed by the scheduled task, and the "Run As User" parameter, which shows the user that will be used to execute the task.

If our current user can modify or overwrite the "Task to Run" executable, we can control what gets executed by the taskusr1 user, resulting in a simple privilege escalation. To check the file permissions on the executable, we use icacls:

Untitled

As can be seen in the result, the BUILTIN\Users  group has full access (F) over the task's binary. This means we can modify the .bat file and insert any payload we like.

Untitled

The next time the scheduled task runs, you should receive the reverse shell with taskusr1 privileges. While you probably wouldn't be able to start the task in a real scenario and would have to wait for the scheduled task to trigger.