Breaking
SecurityConfirmed

Task Host Flaw Now a Ransomware Tool

CISA confirms ransomware gangs are exploiting a Windows Task Host privilege escalation flaw added to KEV in April.

··1 hour ago·3 min read
person using macbook pro on white table
Photo by Dan Nelson on Unsplash

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. The agency updated its Known Exploited Vulnerabilities Catalog (KEV) on Friday to reflect the new ransomware exploitation, adding to a growing list of Microsoft flaws abused in attacks.

Task Host's Role in Windows

Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown. It is foundational to the operating system's process management, making a flaw in it particularly concerning for security teams.

The Vulnerability Details

Tracked as CVE-2025-60710, this Windows privilege escalation security flaw stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices. It was patched by Microsoft in November 2025.

The vulnerability allows local attackers with basic user permissions to gain SYSTEM privileges, the highest level of access on a Windows system. Successful exploitation gives attackers full control of unpatched devices, including the ability to install software, modify data, and create new user accounts with full rights.

From Flagged to Ransomware

CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13, giving Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems. At that time, the agency did not disclose details about the ongoing attacks, and Microsoft had yet to update its security advisory to confirm in-the-wild exploitation.

On Friday, CISA updated its KEV again, flagging the security vulnerability as being abused by ransomware gangs. The agency has not yet shared information about attacks targeting CVE-2025-60710, and a Microsoft spokesperson was not immediately available for comment when BleepingComputer reached out.

"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,"

— CISA warning, as reported by BleepingComputer

CISA urged organizations to "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."

Recent Ransomware Flaw

One week ago, CISA also warned that ransomware gangs have begun exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659) after confirming active exploitation in early July. This pattern shows ransomware operators are quick to adopt newly disclosed flaws.

Government Tracking

Since November 2021, the agency has flagged 383 actively exploited vulnerabilities in various Microsoft products, 112 of which have also been exploited in ransomware attacks. The KEV catalog serves as a key resource for federal agencies and critical infrastructure operators to prioritize patching.

  • 383 actively exploited vulnerabilities in Microsoft products since November 2021
  • 112 of those also exploited in ransomware attacks
  • FCEB agencies given two weeks to secure systems after April 13 addition

Implications for Organizations

The confirmation that ransomware gangs are exploiting CVE-2025-60710 means unpatched Windows 11 and Windows Server 2025 systems face a real and immediate threat. Local attackers who gain initial access through other means—such as phishing or credential theft—can now escalate to SYSTEM privileges and deploy ransomware across the network.

This development could force organizations to prioritize patching this flaw even if they had previously deferred it. The two-week deadline for federal agencies highlights the urgency, but private sector organizations should not wait for a formal directive. The fact that this vulnerability is now linked to ransomware makes it a high-priority target for immediate patching.

As the KEV catalog continues to grow, the line between "actively exploited" and "ransomware-exploited" is becoming increasingly thin. For defenders, this means that any vulnerability in the catalog should be treated as a potential ransomware entry point unless proven otherwise.

#cisa#cve-2025-60710#windows task host#ransomware#kev#privilege escalation

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories