Ransomware Gangs Exploiting High-Severity Windows Task Host Vulnerability
The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has issued a critical warning: ransomware gangs are actively exploiting a high-severity privilege escalation vulnerability in **Windows Task Host**. This flaw, tracked as **CVE-2025-60710**, allows local attackers to gain **SYSTEM** privileges on unpatched **Windows 11** and **Windows Server 2025** devices, posing significant risks to organizations.

**CISA** has confirmed that a critical **Windows Task Host** vulnerability, previously flagged for active exploitation in April, is now being abused by ransomware gangs. This development escalates the threat posed by **CVE-2025-60710**, a privilege escalation flaw that could grant attackers full control over compromised systems.
### Understanding the Vulnerability: CVE-2025-60710
**Task Host** is an integral **Windows** system component responsible for managing DLL-based processes and ensuring their proper termination to prevent data corruption. The vulnerability, identified as **CVE-2025-60710**, is a link following weakness impacting **Windows 11** and **Windows Server 2025** devices.
**Microsoft** issued a patch for this flaw in November 2025. However, unpatched systems remain vulnerable. Successful exploitation allows local attackers, even those with basic user permissions, to elevate their privileges to **SYSTEM** level, effectively taking complete control of the affected device.
### CISA's Escalating Warnings
**CISA** initially added **CVE-2025-60710** to its **Known Exploited Vulnerabilities Catalog (KEV)** on April 13, giving Federal Civilian Executive Branch (**FCEB**) agencies a two-week deadline to apply necessary patches. At that time, **CISA** did not provide specific details on ongoing attacks, and **Microsoft** had not yet updated its security advisory to confirm in-the-wild exploitation.
Recently, **CISA** updated its **KEV** catalog again, specifically flagging **CVE-2025-60710** as being actively abused by ransomware groups. While the agency has not yet disclosed details about these specific ransomware attacks, the update underscores the severe and immediate threat.
"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," **CISA** warned. The agency advises organizations to "apply mitigations per vendor instructions, follow applicable **BOD 22-01** guidance for cloud services, or discontinue use of the product if mitigations are unavailable."
### A Broader Trend of Ransomware Exploitation
This isn't an isolated incident. Just a week prior, **CISA** also alerted the public that ransomware gangs had begun exploiting a **Microsoft SharePoint** remote code execution vulnerability (**CVE-2026-45659**), after confirming its active exploitation in early July.
Since November 2021, **CISA** has identified **383** actively exploited vulnerabilities across various **Microsoft** products. Notably, **112** of these have been leveraged in ransomware attacks, highlighting a persistent and evolving threat landscape that security professionals must continuously monitor.