CISA: Windows Task Host flaw now exploited by ransomware gangs
Reported exploitedWindows Task HostOur summary
CISA has confirmed that ransomware groups are actively leveraging CVE-2025-60710, a high-severity privilege escalation flaw in the Windows Task Host component. This vulnerability, which stems from a link-following weakness, was patched by Microsoft in November 2025 but remained under active attack until CISA added it to the Known Exploited Vulnerabilities catalog on April 13. The bug impacts Windows 11 and Windows Server 2025 systems, allowing local attackers with basic user permissions to elevate their privileges to SYSTEM level. Agencies were directed to apply mitigations within two weeks to prevent further compromise.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.