Cybercriminals Exploit Windows Task Host Vulnerability for Ransomware Attacks

Photo: BleepingComputer
Quick answer
CVE-2025-60710 in Windows Task Host is being exploited by cybercriminals to launch ransomware attacks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are now actively exploiting a critical vulnerability in the Windows Task Host component. Tracked as CVE-2025-60710, this flaw enables attackers with basic user rights to escalate privileges to SYSTEM level, granting full control over compromised systems.
The vulnerability impacts devices running Windows 11 and Windows Server 2025. It stems from a link-following mechanism error, which Microsoft patched in November 2025. Despite the availability of a fix, CISA added the vulnerability to its catalog of actively exploited flaws in April, requiring federal agencies to apply patches within two weeks.
In its latest update, CISA noted that the flaw is being used in ransomware attacks. While specific incident details remain undisclosed, the agency emphasizes that such vulnerabilities pose a severe threat to corporate and government networks. Microsoft has not yet commented on the situation.
CISA previously warned about the exploitation of a vulnerability in Microsoft SharePoint (CVE-2026-45659), which allows arbitrary code execution on servers. Since November 2021, the agency has documented 383 actively exploited vulnerabilities in Microsoft products, 112 of which were used in ransomware attacks.
Common questions
- What is CVE-2025-60710?
- A privilege escalation vulnerability in the Windows Task Host component that allows attackers with basic user rights to gain SYSTEM-level control over affected systems. It affects Windows 11 and Windows Server 2025.
- How to protect against this vulnerability?
- Install the security update released by Microsoft in November 2025. CISA recommends following vendor guidelines and implementing system hardening measures to mitigate risks.
- What are the potential consequences of exploitation?
- Attackers can gain full control over devices, enabling them to deploy malware, encrypt data, or steal sensitive information.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml