Task Host Flaw Now a Ransomware Tool
CISA confirms ransomware gangs are exploiting a Windows Task Host privilege escalation flaw added to KEV in April.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. The agency updated its Known Exploited Vulnerabilities Catalog (KEV) on Friday to reflect the new ransomware exploitation, adding to a growing list of Microsoft flaws abused in attacks.
Task Host's Role in Windows
Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown. It is foundational to the operating system's process management, making a flaw in it particularly concerning for security teams.
The Vulnerability Details
Tracked as CVE-2025-60710, this Windows privilege escalation security flaw stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices. It was patched by Microsoft in November 2025.
The vulnerability allows local attackers with basic user permissions to gain SYSTEM privileges, the highest level of access on a Windows system. Successful exploitation gives attackers full control of unpatched devices, including the ability to install software, modify data, and create new user accounts with full rights.
From Flagged to Ransomware
CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13, giving Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems. At that time, the agency did not disclose details about the ongoing attacks, and Microsoft had yet to update its security advisory to confirm in-the-wild exploitation.
On Friday, CISA updated its KEV again, flagging the security vulnerability as being abused by ransomware gangs. The agency has not yet shared information about attacks targeting CVE-2025-60710, and a Microsoft spokesperson was not immediately available for comment when BleepingComputer reached out.
"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,"
— CISA warning, as reported by BleepingComputer
CISA urged organizations to "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."
Recent Ransomware Flaw
One week ago, CISA also warned that ransomware gangs have begun exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659) after confirming active exploitation in early July. This pattern shows ransomware operators are quick to adopt newly disclosed flaws.
Government Tracking
Since November 2021, the agency has flagged 383 actively exploited vulnerabilities in various Microsoft products, 112 of which have also been exploited in ransomware attacks. The KEV catalog serves as a key resource for federal agencies and critical infrastructure operators to prioritize patching.
- 383 actively exploited vulnerabilities in Microsoft products since November 2021
- 112 of those also exploited in ransomware attacks
- FCEB agencies given two weeks to secure systems after April 13 addition
Implications for Organizations
The confirmation that ransomware gangs are exploiting CVE-2025-60710 means unpatched Windows 11 and Windows Server 2025 systems face a real and immediate threat. Local attackers who gain initial access through other means—such as phishing or credential theft—can now escalate to SYSTEM privileges and deploy ransomware across the network.
This development could force organizations to prioritize patching this flaw even if they had previously deferred it. The two-week deadline for federal agencies highlights the urgency, but private sector organizations should not wait for a formal directive. The fact that this vulnerability is now linked to ransomware makes it a high-priority target for immediate patching.
As the KEV catalog continues to grow, the line between "actively exploited" and "ransomware-exploited" is becoming increasingly thin. For defenders, this means that any vulnerability in the catalog should be treated as a potential ransomware entry point unless proven otherwise.
Sources
- BleepingComputer Original source
Continue Reading
RubyGems Poisoned: Supply Chain Risk Beyond Typos
OpenSourceMalware finds 16 typosquatted RubyGems, but the real risk is package name reuse and unvalidated author fields.
UT San Antonio Cyber Incident Disrupts Start of Term
University takes systems offline after detecting unauthorized activity, delaying registrations and payments ahead of the fall semester.
AI Misuse Warning Hits UK Legal Sector
SRA flags AI hallucinations and data leaks in legal work, urges stronger oversight.