CVE-2025-60710: Microsoft Windows Link Following Vulnerability
Host Process for Windows Tasks Elevation of Privilege Vulnerability
Other sources
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
— Microsoft
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7462Fixed in 10.0.26100.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7462Fixed in 10.0.26200.7392Patch KB5072014
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60710?
CVE-2025-60710 is classified as a medium severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-60710?
To fix CVE-2025-60710, ensure your Windows 11 version 25H2 is updated with the latest security patches.
What is the impact of CVE-2025-60710?
The impact of CVE-2025-60710 allows an authorized user to elevate their privileges on affected systems.
Which versions of Windows are affected by CVE-2025-60710?
CVE-2025-60710 affects Windows 11 version 25H2 for both arm64 and x86_64 architectures.
Who is impacted by CVE-2025-60710?
Users with Windows 11 version 25H2 who have not installed the necessary patches are impacted by CVE-2025-60710.