Published · 5d agoSecurity3 min read
Ransomware crews pick up the Windows Task Host bug Microsoft fixed in November
CVE-2025-60710 turns any logged-in user into SYSTEM on Windows 11 and Server 2025. The fix shipped in November 2025; CISA now says ransomware gangs are using it.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- CISA confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
- Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
- CVE-2025-60710 is a Windows privilege escalation flaw patched by Microsoft in November 2025; it stems from a link following weakness and affects Windows 11 and Windows Server 2025 devices.
- After successful exploitation, local attackers with basic user permissions can gain SYSTEM privileges and take full control of unpatched devices.
- CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and gave Federal Civilian Executive Branch agencies two weeks to secure their systems.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CISA has updated its Known Exploited Vulnerabilities catalog to mark CVE-2025-60710, a Windows Task Host privilege escalation flaw, as being abused by ransomware gangs [1][7]. Microsoft patched it in November 2025, so any Windows 11 or Windows Server 2025 host still exposed has had a fix available for months [3].
The mechanics are unglamorous, which is why this one will work. Task Host is a core Windows component that lets DLL-based processes run in the background and closes them cleanly at shutdown to prevent data corruption [2]. The bug is a link-following weakness in that component affecting Windows 11 and Server 2025 [3]. A local attacker with nothing more than basic user permissions can use it to gain SYSTEM privileges and take full control of an unpatched device [4]. That is not an entry point; it is the second move after one, the step that converts a phished session or a commodity loader into ownership of the machine.
The timeline matters. CISA added CVE-2025-60710 to KEV on April 13 and gave Federal Civilian Executive Branch agencies two weeks to remediate [5], a deadline that fell in late April [3] and roughly five months after the patch shipped [1]. Friday's update does not change what the bug does; it changes who is holding it [7]. Ransomware affiliates are the population that industrialises local privilege escalation, because they need SYSTEM on many hosts quickly rather than on one host quietly.
What is thin here should be stated plainly. CISA has published no details of the attacks it is describing [6][8]. Microsoft has not updated its security advisory to confirm exploitation in the wild [6], and a Microsoft spokesperson was not available for comment when BleepingComputer asked [9]. The ransomware attribution currently rests on CISA's catalogue entry and its standard guidance to apply vendor mitigations, follow BOD 22-01 for cloud services, or stop using the product if mitigations do not exist [10].
The base rate argues against treating this as exceptional. Since November 2021 the agency has flagged 383 actively exploited vulnerabilities in Microsoft products, 112 of which have also been used in ransomware attacks [11] - roughly 29 percent [2]. A week before this update, CISA said ransomware crews had begun exploiting a Microsoft SharePoint remote code execution flaw, CVE-2026-45659, which it had confirmed as actively exploited in early July [12]. The pattern is consistent: KEV listing first, ransomware annotation later, with the patch long since published.
Which puts the burden on verification rather than availability. If your November 2025 cumulative updates were approved, the question is not whether they were approved but which endpoints never took them: laptops that were offline through the window, servers deferred out of a maintenance ring, hosts imaged from media older than the fix, and anything built after the ring closed.
Watch for Microsoft updating the CVE-2025-60710 advisory to acknowledge in-the-wild exploitation [6], and for CISA or incident responders publishing any indicators, since none exist publicly yet [8]. In the meantime, treat local SYSTEM escalation alerts on Windows 11 and Server 2025 as ransomware precursors rather than noise.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CISA confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
- [2]
Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
ReportedView cited source - [3]
CVE-2025-60710 is a Windows privilege escalation flaw patched by Microsoft in November 2025; it stems from a link following weakness and affects Windows 11 and Windows Server 2025 devices.
ReportedView cited source - [4]
After successful exploitation, local attackers with basic user permissions can gain SYSTEM privileges and take full control of unpatched devices.
ReportedView cited source - [5]
CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and gave Federal Civilian Executive Branch agencies two weeks to secure their systems.
ReportedView cited source - [6]
Microsoft has yet to update its security advisory to confirm in-the-wild exploitation of CVE-2025-60710.
ReportedView cited source
Sources & coverage · 5 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comSergiu Gatlan5d agoCISA: Windows Task Host flaw now exploited by ransomware gangs
- scworld.comSteve Zurier5d agoCISA confirms 2025 Windows Task Host flaw exploited by ransomware groups
- bleepingcomputer.comSergiu Gatlan



