CISA says Windows Task Host flaw is now being exploited by ransomware gangs
THE BRIEF
CISA says ransomware operators are exploiting CVE-2025-60710, a high-severity Windows Task Host privilege-escalation vulnerability. The flaw was patched by Microsoft in November 2025 and can allow a local attacker with basic privileges to gain SYSTEM-level access on vulnerable Windows 11 and Windows Server 2025 systems. Its appearance in active ransomware operations matters because privilege escalation is often the step that turns a limited initial foothold into full administrative control. Organizations that deferred older Windows updates, especially on servers or high-value endpoints, may still be exposed. Security teams should treat the issue as an active exploitation problem rather than a routine backlog item and combine patch verification with targeted threat hunting.
WHY IT MATTERS
Ransomware groups rarely rely on a single vulnerability. They chain credential theft, initial access, privilege escalation and lateral movement to reach high-value systems before encryption or data theft begins. A vulnerability that enables SYSTEM access can materially shorten that path. The fact that this bug was patched months ago also highlights a recurring control problem: organizations may focus heavily on newly disclosed CVEs while older, exploitable flaws remain unresolved in patch exceptions or unmanaged assets. For boards and risk teams, the lesson is that vulnerability-management effectiveness depends on verified remediation coverage, not simply patch-release dates or ticket closure rates.
WHO SHOULD CARE
Windows administrators, vulnerability-management teams, SOC analysts, ransomware-response teams, endpoint-security teams, CISOs and IT operations leaders.
WHAT TO DO NOW
- Verify that November 2025 and later Microsoft security updates are installed on all Windows 11 and Windows Server 2025 systems.
- Prioritize domain-connected servers, privileged workstations and other high-value endpoints where local privilege escalation would have the greatest impact.
- Hunt for suspicious privilege-elevation events, unusual service creation, token manipulation and follow-on credential dumping or ransomware tooling.
- Review patch-exception inventories and identify systems that are repeatedly missing monthly Windows security baselines.
- Ensure EDR coverage and tamper protection are enabled on assets that cannot be patched immediately, with compensating controls documented.
VERIFICATION NOTE
CISA exploitation status and ransomware use were reported by BleepingComputer; the vulnerability was previously patched by Microsoft.