Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEexploitVulnerability

CISA Confirms Ransomware Gangs Exploit Windows Task Host Privilege Escalation Flaw

By ogwatermelon
August 20, 2026 4 Min Read
0
August 18, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are now actively exploiting a high-severity Windows Task Host privilege escalation vulnerability tracked as CVE-2025-60710. Consequently, local attackers with basic user permissions can gain SYSTEM privileges and take full control of unpatched Windows 11 and Windows Server 2025 devices.

What Happened: Ransomware Gangs Exploit Windows Task Host Flaw for SYSTEM Privileges

Microsoft patched CVE-2025-60710 in November 2025, yet the flaw remained under active exploitation for months. CISA first added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on April 13, 2026, ordering federal agencies to patch within two weeks. However, on August 14, 2026, CISA updated the KEV entry to flag the vulnerability as being actively abused by ransomware gangs.

Task Host is a core Windows system component that allows DLL-based processes to run in the background. Moreover, it prevents data corruption by ensuring processes close properly during shutdown. The vulnerability stems from a link following weakness in this component. Therefore, successful exploitation lets an attacker escalate from a standard user account to full SYSTEM privileges.

While CISA has not shared technical details about specific attack campaigns, the confirmation of ransomware exploitation raises the stakes significantly. Ransomware operators typically chain privilege escalation flaws with other initial access techniques to deploy file-encrypting payloads across entire networks.

Technical Details of CVE-2025-60710

CVE-2025-60710 is classified as a link following vulnerability with a high severity rating. The flaw exists in the Windows Task Host component that manages background DLL processes during system shutdown sequences.

The vulnerability affects the following Windows versions:

  • Windows 11 (multiple builds)
  • Windows Server 2025

Furthermore, the attack vector is local, meaning an attacker must already have valid user-level access to the target system. This makes the flaw particularly dangerous in environments where attackers have already breached the perimeter through phishing, stolen credentials, or unpatched remote access vulnerabilities. Once inside, they can escalate privileges and move laterally with SYSTEM-level access.

The CVSS scoring for this vulnerability reflects high impact but requires local access. Nonetheless, ransomware groups have demonstrated repeatedly that local privilege escalation is a critical step in their kill chains.

Business and Operational Impact

The confirmation of ransomware exploitation transforms CVE-2025-60710 from a routine patch item into an urgent remediation priority. Organizations running affected Windows versions face several serious risks.

  • Complete system compromise: SYSTEM privileges grant attackers unrestricted access to files, registry keys, and security policies
  • Ransomware deployment: Elevated privileges enable mass encryption across endpoints and servers
  • Lateral movement: Attackers can pivot to other systems using compromised high-privilege credentials
  • Persistence establishment: SYSTEM access allows installation of rootkits, backdoors, and scheduled tasks
  • Data exfiltration: Attackers can steal sensitive information before deploying ransomware

Moreover, organizations in regulated industries may face compliance penalties if they fail to patch known exploited vulnerabilities promptly. CISA’s KEV Catalog serves as a definitive signal that threat actors are weaponizing this flaw in the wild.

Mitigation and Recommendations

CISA urges all organizations to apply mitigations per vendor instructions and follow BOD 22-01 guidance for cloud services. In addition, Microsoft released patches for this vulnerability in November 2025 as part of its monthly security update cycle.

Immediate Actions for Defenders

  1. Apply the November 2025 Windows security update immediately on all affected systems
  2. Verify patch compliance across Windows 11 and Windows Server 2025 endpoints
  3. Review endpoint detection alerts for suspicious privilege escalation activity
  4. Audit local user accounts and remove unnecessary privileges
  5. Enable Microsoft Defender Attack Surface Reduction rules where available

Detection Guidance

Security teams should monitor for anomalous processes spawning with elevated privileges from standard user contexts. Furthermore, Windows Event Log entries related to service creation, scheduled task modifications, and token impersonation may indicate exploitation attempts. EDR solutions should be tuned to alert on Task Host process anomalies.

Long-Term Hardening

  • Implement least-privilege access controls for all user accounts
  • Deploy application whitelisting to prevent unauthorized code execution
  • Segment networks to limit lateral movement opportunities
  • Maintain offline backups that are tested regularly for ransomware recovery

Bottom line: CVE-2025-60710 is no longer a theoretical risk. Ransomware gangs are actively exploiting this Windows Task Host flaw to gain SYSTEM privileges and deploy payloads. Patch immediately, monitor for exploitation indicators, and assume compromised credentials may already be present in your environment.

Incident Summary

CVE ID / Incident: CVE-2025-60710
Affected Systems: Windows 11, Windows Server 2025
Disclosure Date: April 13, 2026 (CISA KEV); August 14, 2026 (ransomware exploitation confirmed)
Patch Status: Available since November 2025 Patch Tuesday
Severity: High (privilege escalation to SYSTEM)
Known Exploitation: Active exploitation confirmed by CISA; ransomware campaigns observed

References

  1. BleepingComputer, “CISA: Windows Task Host flaw now exploited by ransomware gangs,” August 18, 2026.
  2. CISA, “Known Exploited Vulnerabilities Catalog: CVE-2025-60710,” updated August 14, 2026.
  3. Microsoft, “CVE-2025-60710 Security Update Guide,” November 2025.
  4. NIST NVD, “CVE-2025-60710 Detail,” accessed August 18, 2026.

Tags:

CVEExploitVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

ShieldBreak CVE Microsoft Defender Zero-Day

Next

Critical Windows IKE Extension RCE CVE-2026-33824 Under Active Exploitation

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.