Ransomware Gangs Now Weaponize Windows Task Host Privilege Escalation Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirms that ransomware gangs are now exploiting CVE-2025-60710, a high-severity Windows Task Host vulnerability. Task Host is a core Windows component that runs DLL-based processes in the background and ensures they close properly during shutdown to prevent data corruption. The flaw, which stems from a link following weakness, affects Windows 11 and Windows Server 2025 devices.

The vulnerability allows local attackers with only basic user permissions to gain SYSTEM privileges after successful exploitation, giving them full control over unpatched devices. Microsoft patched the issue in its November 2025 security update and urges all customers to apply the patch. CISA first added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog on April 13, giving Federal Civilian Executive Branch agencies two weeks to secure their systems. On Friday, the agency updates the catalog entry again to flag that ransomware gangs are actively abusing the vulnerability.

CISA has not shared technical details about the ongoing attacks, and Microsoft has yet to update its security advisory to confirm in-the-wild exploitation. The agency warns that this type of vulnerability is a frequent attack vector for malicious actors and poses significant risks to the federal enterprise, advising organizations to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. The news follows a similar CISA warning one week earlier about ransomware gangs exploiting a Microsoft SharePoint remote code execution flaw, CVE-2026-45659, bringing the total number of actively exploited Microsoft vulnerabilities flagged since November 2021 to 383.

Read More at the original source →