A Windows task scheduler API function does not check permissions – so any potential local bad actor can alter them to gain elevated privileges.
Source: Threadpost