تخطي إلى المحتوى الرئيسي
Cyber News BleepingComputer 3 days ago

CISA: Windows Task Host flaw now exploited by ransomware gangs

Bl
BleepingComputer

Windows keyboard

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.

Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.

Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices.

image

Following successful exploitation, local attackers with basic user permissions can gain SYSTEM privileges and take full control of unpatched devices.

While it didn't share any details regarding ongoing attacks and Microsoft has yet to update its security advisory to confirm in-the-wild exploitation, CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems.

"We addressed CVE-2025-60710 in our November 2025 security update release and recommend customers apply the update to remain protected," a Microsoft spokesperson told BleepingComputer. "Customers who have already applied the update are protected and do not need to take further action."

Get the report

View Original Report

This intelligence was aggregated from BleepingComputer.

Read on Source