Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware gangs exploit Windows Task Host flaw

Cluttered office workstation with laptop and monitor on desk.

"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA warned.

CVE-2025-60710: Task Host, link-following, and SYSTEM escalation

The vulnerability at the center of CISA's notice—tracked as CVE-2025-60710—is a high-severity Windows privilege escalation flaw in Task Host, a core Windows component that lets DLL-based processes run in the background and ensures they close cleanly at shutdown. Microsoft patched the issue in November 2025. The underlying bug is described as a link-following weakness that affects Windows 11 and Windows Server 2025 devices.

Per the bulletin, a local attacker with only basic user permissions who successfully exploits the flaw can elevate to SYSTEM privileges and take full control of an unpatched device.

CISA's escalation: active exploitation listed April 13, then flagged for ransomware abuse

CISA added CVE-2025-60710 to its Known Exploited Vulnerabilities (KEV) catalog as actively exploited on April 13 and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems. On Friday, the agency updated the KEV entry to explicitly flag the vulnerability as being abused by ransomware gangs. CISA has not shared technical details or public samples of the attacks it says are occurring.

Vendor status and guidance: patch in November 2025, advisory gaps, and mitigations

Microsoft issued a patch for CVE-2025-60710 in November 2025, but the company had not updated its publicly available security advisory to confirm in-the-wild exploitation at the time of reporting. A Microsoft spokesperson was not immediately available for comment when BleepingComputer reached out.

CISA urged organizations to "apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable." The agency also noted the frequency with which this class of vulnerability is used by malicious actors when warning of risks to the federal enterprise.

Related activity: ransomware focus and prior SharePoint warning

The KEV update is the latest signal that ransomware operators are leveraging known privilege escalation vectors against Windows environments. One week before the latest Task Host alert, CISA warned that ransomware gangs had begun exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659) after confirming active exploitation in early July.

Since November 2021, CISA has flagged 383 actively exploited vulnerabilities in various Microsoft products; 112 of those have also been linked to ransomware attacks, according to the agency's published counts.

What this means for technologists, FCEB agencies, and enterprise defenders

  • Technologists and security teams: Verify patch status for Windows 11 and Windows Server 2025 machines and apply Microsoft’s November 2025 patch or vendor-recommended mitigations. Expect that privilege escalation flaws like link-following in Task Host are attractive to post-compromise actors seeking SYSTEM-level control.
  • FCEB agencies: CISA gave a two-week remediation window when it added CVE-2025-60710 to the KEV on April 13. Agencies are being directed to follow BOD 22-01 guidance for cloud services where applicable or to discontinue use if mitigations are unavailable.
  • Affected enterprises and procurement leaders: The KEV update underscores a pattern—CISA’s catalog has repeatedly identified Microsoft product flaws later tied to ransomware. Procurement and asset-inventory processes should ensure visibility into Windows 11 and Windows Server 2025 endpoints and their patch posture.

Two clear threads run through these notifications: the technical vector (a link-following weakness in a system process) and the operational pattern (ransomware actors exploiting known, patched or unpatched Microsoft flaws). CISA's public posture—adding the entry to KEV, imposing a timed directive for federal agencies, and then flagging ransomware abuse—signals that defenders should treat CVE-2025-60710 as an immediate, actionable priority.

Original story: https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/