CVE Tools

CISA: Windows Task Host flaw now exploited by ransomware gangs

BleepingComputerBy Sergiu Gatlan

Reported exploitedWindows Task Host

Our summary

CISA has confirmed that ransomware groups are actively leveraging CVE-2025-60710, a high-severity privilege escalation flaw in the Windows Task Host component. This vulnerability, which stems from a link-following weakness, was patched by Microsoft in November 2025 but remained under active attack until CISA added it to the Known Exploited Vulnerabilities catalog on April 13. The bug impacts Windows 11 and Windows Server 2025 systems, allowing local attackers with basic user permissions to elevate their privileges to SYSTEM level. Agencies were directed to apply mitigations within two weeks to prevent further compromise.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store