• News/
  • bleepingcomputer-20260818103216

CISA: Windows Task Host flaw now exploited by ransomware gangs

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 18, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown. Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices. Following successful exploitation, local attackers with basic user permissions can gain SYSTEM privileges and take full control of unpatched devices. While it didn't share any details regarding ongoing attacks and Microsoft has yet to update its security advisory to confirm in-the-wild exploitation, CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems. "We addressed CVE-2025-60710 in our November 2025 security update release and recommend customers apply the update to remain protected," a Microsoft spokesperson told BleepingComputer. "Customers who have already applied the update are protected and do not need to take further action." On Friday, CISA updated its Known Exploited Vulnerabilities Catalog (KEV) again, flagging the security vulnerability...

Read full article

Affected Software

1 affected component
Microsoft Windows Task Host=Windows 11, =Windows Server 2025

Frequently Asked Questions

1

Which systems are affected by CVE-2025-60710?

CVE-2025-60710 affects Windows 11 and Windows Server 2025 devices. It is a Windows Task Host privilege-escalation flaw caused by a link-following weakness.

2

What could an attacker gain by exploiting this flaw?

A local attacker with basic user permissions can exploit the flaw to obtain SYSTEM privileges and take full control of an unpatched device. The vulnerability was patched by Microsoft in November 2025.

3

What is confirmed about active exploitation?

CISA has added the vulnerability to its Known Exploited Vulnerabilities Catalog and says ransomware gangs are exploiting it. However, CISA did not provide details of the ongoing attacks, and Microsoft has not updated its advisory to confirm in-the-wild exploitation.

4

What remediation action does the CISA listing imply?

Federal Civilian Executive Branch agencies were given two weeks after CISA added the flaw to the catalog on April 13 to secure affected systems. Organizations using affected, unpatched Windows devices should prioritize applying Microsoft's patch.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203