CISA Confirms Windows Task Host Flaw Used in Ransomware Attacks


microsoft researcher legal
Image credit: Microsoft

CISA confirms Windows Task Host flaw CVE-2025-60710 is now being exploited in ransomware attacks, according to an updated warning from the US Cybersecurity and Infrastructure Security Agency.

The CVE-2025-60710 vulnerability affects Windows Task Host and allows a local attacker to elevate privileges to SYSTEM.

Microsoft patched the high-severity flaw in November 2025. CISA first added it to its Known Exploited Vulnerabilities Catalog on April 13, 2026, after confirming active exploitation.

CISA has now updated the catalog again to indicate that attackers are using the vulnerability in ransomware campaigns.

CVE-2025-60710 can give attackers SYSTEM privileges

CVE-2025-60710 stems from a link-following weakness in Windows Task Host. The vulnerability affects Windows 11 and Windows Server 2025.

An attacker with basic local user privileges can exploit the flaw to gain SYSTEM-level access.

That level of access can give attackers extensive control over an unpatched Windows device, making the vulnerability particularly dangerous when attackers have already gained an initial foothold on a system.

CISA confirms ransomware exploitation

CISA has not identified the ransomware groups exploiting CVE-2025-60710 or disclosed specific campaigns linked to the flaw.

The agency also has not provided technical details explaining how ransomware operators are exploiting the vulnerability.

Microsoft’s security advisory has not yet been updated to acknowledge exploitation in the wild.

CISA warns that vulnerabilities added to the KEV Catalog can pose a significant risk to organizations because attackers have demonstrated that they can exploit them in real-world attacks.

Organizations should install Microsoft’s security update

Organizations running affected Windows versions should install Microsoft’s available security update for CVE-2025-60710.

Federal agencies must address vulnerabilities included in CISA’s KEV Catalog within the required remediation period. CISA also recommends discontinuing affected products when vendors do not provide suitable mitigations.

The latest warning comes as Microsoft continues addressing other Windows security issues. The company recently patched the LegacyHive Windows zero-day and is working on addressing ShieldBreak.

Separately, a hacker recently claimed that 3.64 million employee records were stolen from Azure environments.

Via BleepingComputer

More about the topics: microsoft, Ransomware, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages