CISA: Windows Task Host flaw now exploited by ransomware gangs

CISA: Windows Task Host flaw now exploited by ransomware gangs
CISA confirmed that ransomware gangs are exploiting CVE-2025-60710, a high-severity Windows Task Host privilege escalation flaw affecting Windows 11 and Windows Server 2025. The agency added the vulnerability to its KEV catalog and urged federal agencies to patch it, while Microsoft has not yet publicly confirmed in-the-wild exploitation. #CVE-2025-60710 #CISA #WindowsTaskHost #Windows11 #WindowsServer2025

Keypoints

  • CVE-2025-60710 is a Windows Task Host privilege escalation vulnerability.
  • The flaw affects Windows 11 and Windows Server 2025 devices.
  • Local attackers can gain SYSTEM privileges after successful exploitation.
  • CISA added the vulnerability to its KEV catalog as actively exploited.
  • CISA says ransomware gangs are abusing the flaw and urges immediate patching.

Read More: https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/