CISA has warned that ransomware gangs are exploiting a high-severity Windows Task Host flaw that lets attackers gain full control of unpatched Windows devices.
The vulnerability affects Windows 11 and Windows Server 2025 systems. Microsoft released a security update in November 2025, but organisations that have not installed it remain exposed.
Windows Task Host flaw gives attackers SYSTEM access
The Windows Task Host flaw, tracked as CVE-2025-60710, is a local privilege escalation vulnerability.
Task Host is a core Windows component that manages background processes based on DLL files. It also helps those processes close safely during shutdown, reducing the risk of data corruption.
However, the flaw allows a local attacker with standard user access to elevate their permissions to SYSTEM level. SYSTEM is one of the highest privilege levels in Windows, giving an attacker broad control over the affected machine.
The vulnerability stems from a link-following weakness. Attackers could exploit it to manipulate how Windows handles files or directories and then gain elevated access.
CISA confirms ransomware exploitation
CISA added CVE-2025-60710 to its Known Exploited Vulnerabilities catalog on April 13 after confirming active exploitation.
At that time, the agency gave Federal Civilian Executive Branch agencies two weeks to secure vulnerable systems. CISA did not share details about the attacks or identify the threat actors involved.
On Friday, the agency updated the entry again and confirmed that ransomware gangs now abuse the vulnerability.
Neither CISA nor Microsoft has publicly disclosed which ransomware operations use the flaw, how they gain initial access, or which organisations have suffered attacks.
Agencies and businesses should patch affected systems
CISA urged organisations to apply Microsoft’s mitigations as soon as possible. The agency warned that vulnerabilities of this kind often provide an effective route for malicious actors seeking to expand access inside a network.
Businesses should ensure that Windows 11 and Windows Server 2025 devices have the November 2025 security updates installed. Security teams should also review systems for unusual privilege changes, suspicious file activity and unexpected processes running with SYSTEM permissions.
The warning follows a similar CISA alert from last week concerning a Microsoft SharePoint remote code execution flaw, CVE-2026-45659. The agency also confirmed ransomware exploitation of that vulnerability.
Since November 2021, CISA has added 383 actively exploited vulnerabilities affecting Microsoft products to its catalog. Of those, 112 have also appeared in ransomware attacks.


0 responses to “CISA Warns Ransomware Gangs Exploit Windows Task Host Flaw”