The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are exploiting a high-severity Windows Task Host vulnerability tracked as CVE-2025-60710. The security flaw was reportedly exploited in the wild in April and can allow attackers to elevate privileges on vulnerable Windows devices.
Windows Task Host is a core operating system component that enables DLL-based processes to run in the background. It also helps prevent data corruption by ensuring that running processes close properly when Windows shuts down.
Tracked as CVE-2025-60710, the Windows privilege escalation vulnerability was patched by Microsoft in November 2025. The flaw is caused by an improper link resolution before file access issue and affects Windows 11 and Windows Server 2025 devices.
A successful exploit could allow a local attacker with basic user privileges to gain SYSTEM-level permissions and take complete control of an unpatched Windows device. Attackers could then install malicious software, alter system settings, access sensitive data, or deploy ransomware.
Details about the attacks exploiting CVE-2025-60710 have not been publicly disclosed. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on April 13, requiring Federal Civilian Executive Branch (FCEB) agencies to secure affected systems within two weeks. Organizations can review Microsoft’s CVE-2025-60710 security advisory and the CISA KEV listing for additional guidance.
CISA later updated its Known Exploited Vulnerabilities Catalog to identify CVE-2025-60710 as being exploited by ransomware groups.
U.S. cybersecurity agencies have not released details about attacks targeting this Windows Task Host vulnerability. A Microsoft spokesperson was also unavailable for comment when contacted by BleepingComputer.
“These types of vulnerabilities are a frequent attack vector by malicious cyber attackers and pose significant risks to federal enterprises,” CISA warned. “Apply mitigations as directed by the vendor and follow the BOD 22-01 guidance applicable to your cloud service, or discontinue use of the product if mitigations are not available.”
CISA also recently warned that ransomware groups had begun exploiting the Microsoft SharePoint remote code execution vulnerability CVE-2026-45659 after detecting active attacks in early July.
Since November 2021, CISA has added 383 vulnerabilities in Microsoft products to its KEV catalog. Of those vulnerabilities, 112 have also been linked to ransomware attacks. Organizations using Windows 11 or Windows Server 2025 should prioritize applying Microsoft’s security updates and monitoring for suspicious privilege escalation activity.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




