Ransomware Gangs Exploit Critical Windows Task Host Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are actively exploiting a high-severity Windows privilege escalation flaw, CVE-2025-60710, which affects Windows 11 and Windows Server 2025 systems.
The vulnerability, patched by Microsoft in November 2025, stems from a link-following weakness in the Windows Task Host component a core system process that manages background DLL execution and prevents data corruption during shutdowns. Successful exploitation allows attackers with basic user permissions to escalate privileges to SYSTEM level, granting full control over unpatched devices.
CISA added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog on April 13, mandating Federal Civilian Executive Branch (FCEB) agencies to remediate it within two weeks. While neither CISA nor Microsoft has disclosed details about ongoing attacks, the agency updated its catalog on Friday to explicitly warn of ransomware exploitation.
This follows a recent alert about ransomware gangs targeting another Microsoft vulnerability, CVE-2026-45659 (a SharePoint remote code execution flaw), after confirmed exploitation in early July. Since November 2021, CISA has flagged 383 actively exploited Microsoft vulnerabilities, with 112 linked to ransomware attacks.
Microsoft Security cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security
"id": "MIC1787056197",
"linkid": "microsoft-security",
"type": "Ransomware",
"date": "4/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Public Sector',
'location': 'United States',
'name': 'Federal Civilian Executive Branch (FCEB) '
'agencies',
'type': 'Government'}],
'attack_vector': 'Privilege Escalation',
'date_publicly_disclosed': '2025-11',
'description': 'The U.S. Cybersecurity and Infrastructure Security Agency '
'(CISA) has confirmed that ransomware groups are actively '
'exploiting a high-severity Windows privilege escalation flaw, '
'CVE-2025-60710, which affects Windows 11 and Windows Server '
'2025 systems. The vulnerability stems from a link-following '
'weakness in the Windows Task Host component, allowing '
'attackers with basic user permissions to escalate privileges '
'to SYSTEM level. CISA added the flaw to its Known Exploited '
'Vulnerabilities (KEV) Catalog on April 13, mandating Federal '
'Civilian Executive Branch (FCEB) agencies to remediate it '
'within two weeks.',
'impact': {'operational_impact': 'Full control over unpatched devices',
'systems_affected': 'Windows 11, Windows Server 2025'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'corrective_actions': 'Patch deployment, privilege '
'escalation monitoring',
'root_causes': 'Link-following weakness in Windows '
'Task Host component'},
'recommendations': "Apply Microsoft's November 2025 patch for CVE-2025-60710; "
'monitor for privilege escalation attempts.',
'references': [{'source': 'CISA Known Exploited Vulnerabilities Catalog'},
{'source': 'Microsoft Security Update'}],
'regulatory_compliance': {'regulatory_notifications': 'CISA KEV Catalog '
'addition (April 13, '
'2025)'},
'response': {'remediation_measures': 'Patch management (Microsoft November '
'2025 update)'},
'stakeholder_advisories': 'CISA mandate for FCEB agencies to remediate within '
'two weeks.',
'threat_actor': 'Ransomware Gangs',
'title': 'Ransomware Gangs Exploit Critical Windows Task Host Vulnerability',
'type': 'Ransomware',
'vulnerability_exploited': 'CVE-2025-60710'}